← Vulnerability feed

Vulnerability record · CVE-2026-27593 · published 24 February 2026

CVE-2026-27593: Statamic weak password recovery vulnerability

Statamic · Statamic

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid account on the site, and the actual user must blindly click the link in their email even though they didn't request the reset. This has been fixed in 6.3.3 and 5.73.10.

8.8 CVSS 3.1 High EPSS 0.55% · top 56.1% CWE-640 · Weak password recovery
8.8CVSS 3.1 base score
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid account on the site, and the actual user must blindly click the link in their email even though they didn't request the reset. This has been fixed in 6.3.3 and 5.73.10.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-27593 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47129Statamic unrestricted file upload vulnerabilityStatmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload fi…EPSS 1.1%9.8CVE-2021-45364Statamic vulnerabilityA Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an err…EPSS 1.7%8.8CVE-2026-27939Statamic improper authentication vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control P…EPSS 0.46%8.8CVE-2023-48217Statamic code injection vulnerabilityStatamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look…EPSS 1.1%8.8CVE-2017-11422Statamic incorrect permission assignment vulnerabilityStatamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods…EPSS 0.87%8.7CVE-2026-33172Statamic cross-site scripting vulnerabilityStatamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset r…EPSS 0.36%8.7CVE-2026-25759Statamic cross-site scripting vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allo…EPSS 0.44%8.6CVE-2026-28423Statamic server-side request forgery (ssrf) vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide image manipulation is used in…EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2026-27593), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.