CVE-2026-27593 - Vulnerability Analysis
CriticalCVSS: 9.3Last Updated: February 25, 2026
Statmatic - Authentication Bypass
Overview
Statmatic < 6.3.3 and < 5.73.10 contains an authentication bypass caused by a flaw in the password reset feature, letting attackers reset passwords by capturing tokens if users click unsolicited reset links, exploit requires user interaction.
Severity & Score
Impact
Attackers can reset user passwords by capturing tokens, leading to account takeover.
Mitigation
Update to versions 6.3.3 and 5.73.10 or later.
References
- https://github.com/statamic/cms/security/advisories/GHSA-jxq9-79vj-rgvw
- https://github.com/statamic/cms/commit/6fdd03324982848e8754f2edd2265262d361714e
- https://github.com/statamic/cms/commit/78e63dfcf705b116d5ac0f7f7f5a1a69be63d1be
- https://github.com/statamic/cms/commit/b2be592ddfb588bcb88c9be454f3590e14b145b0
- https://github.com/statamic/cms/releases/tag/v5.73.10
- https://github.com/statamic/cms/releases/tag/v6.3.3
Social Media Activity(3 posts)
PSA for Statamic folks - update your sites ASAP! ā ļø A CRITICAL vuln was discovered that allows full account takeover via password resets! š± All the details: https://cvereports.com/reports/CVE-2026-27593 #Laravel
View original postšØ Statamic CMS CRITICAL vuln (CVE-2026-27593): Weak password reset lets attackers hijack accounts if users click a malicious link. Patch to 6.3.3/5.73.10+, educate users, enable MFA. Details: https://radar.offseq.com/threat/cve-2026-27593-cwe-640-weak-password-recovery-mech-d0c0ac0e #OffSeq #Statamic #CVE202627593 #infosec
View original postš“ CVE-2026-27593 - Critical (9.3) Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. T... š https://www.thehackerwire.com/vulnerability/CVE-2026-27593/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-27593
- Severity
- Critical
- CVSS Score
- 9.3
- Type
- broken_authentication
- Status
- confirmed
- EPSS
- 1.7%
- Social Posts
- 3
CWE
- CWE-640
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N