CVE-2026-64665
Statamic · CMS
Statamic CMS is vulnerable to authentication bypass and spoofing issues, allowing unauthorized access to restricted areas of the platform.
Executive summary
A critical authentication bypass flaw in Statamic CMS permits unauthenticated remote attackers to gain unauthorized access, posing a severe risk to data integrity and administrative control.
Vulnerability
The software suffers from improper authentication (CWE-287) and authentication bypass via spoofing (CWE-290). These flaws allow an unauthenticated attacker to manipulate authentication mechanisms to gain unauthorized access.
Business impact
The ability to bypass authentication in a CMS provides an attacker with administrative control over the website, potentially leading to full data compromise, unauthorized modification of site content, and complete system takeover. With a CVSS score of 8.1, this vulnerability presents a high risk to the confidentiality and integrity of any organization relying on Statamic.
Remediation
Immediate Action: Update Statamic CMS to version 5.74.1 or 6.24.0 immediately to resolve the authentication vulnerability.
Proactive Monitoring: Review web access logs for unusual login attempts, unauthorized administrative actions, or patterns indicating automated exploitation attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block suspicious authentication requests or bypass attempts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations using Statamic CMS must prioritize upgrading to the patched versions immediately. Given the high impact of unauthorized administrative access, failing to patch this vulnerability exposes the entire web environment to significant risk.