Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27593

31
FAUCET Score

CVE-2026-27593 is a high-severity vulnerability affecting Statamic CMS versions prior to 6.3.3 and 5.73.10. It allows an unauthenticated attacker to reset a user's password by knowing their email address and tricking the user into clicking a malicious password reset link. The CVSS score of 8.8 indicates a critical risk, with high impact on confidentiality, integrity, and availability, requiring user interaction for successful exploitation. There is currently no public exploit code available, and it is not known to be actively exploited, though it has received some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.73.10CPE matchmatch criteria
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.3.3CPE matchmatch criteria
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.3CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 40th percentile among its peer group of 14,855 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: statamic/cmsFixed in: 6.3.3
composerpatch availablevia ghsa
Product: statamic/cmsFixed in: 5.73.10
composerpatch availablevia ghsa
Product: statamic/cmsFixed in: 6.7.1

Vendor Advisories (1)

composerGHSA-jxq9-79vj-rgvwcritical

Statamic is vulnerable to account takeover via password reset link injection

Feb 24, 2026

References

github.com / statamic/cms/commit/6fdd03324982848e8754f2edd2265262d361714e
Patch
github.com / statamic/cms/commit/78e63dfcf705b116d5ac0f7f7f5a1a69be63d1be
Patch
github.com / statamic/cms/commit/b2be592ddfb588bcb88c9be454f3590e14b145b0
Patch
github.com / statamic/cms/releases/tag/v5.73.10
Release Notes
github.com / statamic/cms/releases/tag/v6.3.3
Release Notes
github.com / statamic/cms/security/advisories/GHSA-jxq9-79vj-rgvw
Vendor Advisory