CVE-2026-64664: Infoleak
Impact An authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belongs to an existing user, without having permission to view users.
The endpoint only exposed user existence, not any of its data.
Patches This has been fixed in 5.74.1 and 6.24.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/statamic/cmsto a version that resolves this vulnerability.Fixed in 6.24.0 - Upgrade
Upgrade
composer/statamic/cmsto a version that resolves this vulnerability.Fixed in 5.74.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.74.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.24.0