statamic/cms is vulnerable to Authentication Bypass
81
High Risk
When OAuth login is enabled with a provider that does not guarantee verified email addresses, Statamic matches the returned email to an existing account without confirming that the email is verified. An unauthenticated actor using such a provider can sign in as an existing user, potentially including a super admin, without knowing their password. Exploitation requires OAuth to be explicitly enabled with a provider that allows unverified emails. The fix adds an email-verification check before matching an OAuth login to an existing user.
You are affected if you are using a version that falls within the vulnerable range and you have OAuth login enabled with a provider that does not guarantee verified email addresses.
statamic/cms is vulnerable to Authentication Bypass in versions 0.0.1 - 5.74.0 and 6.0.0 - 6.23.0.
Upgrade the statamic/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant