Résumé
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Détails de l’avis
Impact
An authenticated Control Panel user could use an endpoint intended for the user creation wizard to determine if a given email address belongs to an existing user, without having permission to view users.
The endpoint only exposed user existence, not any of its data.
Patches
This has been fixed in 5.74.1 and 6.24.0.
Références
- https://github.com/advisories/GHSA-225x-3jhx-wh4q
- https://github.com/statamic/cms/security/advisories/GHSA-225x-3jhx-wh4q
- https://github.com/statamic/cms/pull/14905
- https://github.com/statamic/cms/commit/aea68053cedab5c79d10102820b57345a7d7102e
- https://github.com/statamic/cms/releases/tag/v5.74.1
- https://github.com/statamic/cms/releases/tag/v6.24.0
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-72804
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
- HIGHCVE-2026-55178
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
- HIGHCVE-2026-70473
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
- HIGHCVE-2026-59216
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
- HIGHCVE-2026-25038
Gitea: Unauthorized Access to Labels of Private Organizations
- MEDIUMCVE-2026-50105
Gitea: RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)