CVE-2026-27593 is a high-severity vulnerability affecting Statamic CMS versions prior to 6.3.3 and 5.73.10. It allows an unauthenticated attacker to reset a user's password by knowing their email address and tricking the user into clicking a malicious password reset link. The CVSS score of 8.8 indicates a critical risk, with high impact on confidentiality, integrity, and availability, requiring user interaction for successful exploitation. There is currently no public exploit code available, and it is not known to be actively exploited, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.73.10CPE matchmatch criteria | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.3.3CPE matchmatch criteria | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.