CVE-2026-27593Disclosure(statamic / statamic)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch statamic statamic systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email address of a valid account on the site, and the actual user must blindly click the link in their email even though they didn't request the reset. This has been fixed in 6.3.3 and 5.73.10.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • statamic

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 5 mentions (2026-02-25); latest day: 1
  • 11 total mentions across 4 days

Affected systems

Vendors
Products
statamic

Deep dive

Activity timeline11 mentions / 4d
01345Mentions · 2026-02-24: 3Mentions · 2026-02-25: 5Mentions · 2026-03-20: 2Mentions · 2026-06-13: 1PoC Mentioned / Linked · 2026-03-20: 1Active Exploitation · 2026-03-20: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-02-24: 3Technical Details · 2026-02-25: 3Technical Details · 2026-03-20: 1Technical Details · 2026-06-13: 102-2402-2503-2006-13
Signal classification4 categories
Disclosure
545.5%
General
327.3%
Patch
218.2%
Exploit
19.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-243
Disclosure2Patch1
2026-02-255
Disclosure2General2Patch1
2026-03-202
Exploit1General1
2026-06-131
Disclosure1
Full discourse11 posts
  • Yassin Mohamed 🇵🇸@0xblackkk
    Exploit

    I got 3 CVEs: CVE-2026-27593: Patched before, but still exploitable. Achieved Admin Account Takeover. CVE-2026-4420: Stored XSS → chained → 1-click Account Takeover CVE-2026-33177: Broken Access Control via alternative controller bypass. Full writeups in comments. https://t.co/zLP0GVo4kY

    Post summary

    The tweet asserts successful exploitation of three CVEs, shows proof of exploit via admin takeover, outlines specific vulnerability mechanics, references a patch, and links to further writeups.

    212070305.2K
    119 followersView on X
  • Stephen Rees-Carter@valorin
    Disclosure

    PSA for @statamic folks - update your sites ASAP! ⚠️ A CRITICAL vuln was discovered that allows full account takeover via password resets! 😱 All the details: https://cvereports.com/reports/CVE-2026-27593

    Post summary

    A critical vulnerability (CVE-2026-27593) in Statamic permits full account takeover through password resets; users are urged to update their sites immediately.

    0501731.8K
    5.4K followersView on X
  • Yassin Mohamed 🇵🇸@0xblackkk
    General

    CVE-2026-27593 (Critical) https://everythingblackkk.gitbook.io/everythingblackkk/my-cve/cve-2026-27593-critical CVE-2026-33177 (Moderate) https://everythingblackkk.gitbook.io/everythingblackkk/my-cve/cve-2026-33177-moderate CVE-2026-4420 (Moderate) https://youtu.be/B5F-tYDHi_I

    Post summary

    The passage merely lists three CVE identifiers with corresponding URLs, providing no substantive information on exploitation, patches, or technical details.

    01076630
    119 followersView on X
  • neospring@ChrisAlupului
    Disclosure

    Want your name on a CVE? I just published how I found one in Statamic CMS (CVE-2026-27593), an unauthenticated password reset link injection. A full YouTube series is coming that breaks down this find plus 15+ more I've got queued. Built for OSCP/CPTS folks ready to go from labs to real disclosure. #htb #cybersecurity #ethicalhacking #pentesting https://alupului.com/blog/cve-2026-27593-statamic-password-reset-link-injection

    Post summary

    The author announces discovery of CVE-2026-27593, a password reset link injection vulnerability in Statamic CMS, and plans a detailed YouTube series, but no exploit, patch, or active exploitation is reported.

    00010139
    1.2K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27593: CVE-2026-27593: Statamic's 'Choose Your Own Adventure' Password Reset A critical vulnerability in Statamic CMS turns the password reset feature into an account takeover weapon. By injecting a malicious base URL into the reset request, ... https://cvereports.com/reports/CVE-2026-27593

    Post summary

    Statamic CMS has a critical password reset flaw that allows attackers to inject a malicious base URL, enabling account takeover.

    0001054
    31 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A vulnerability in `Statamic CMS` (CVE-2026-27593) allows account takeover via password reset link injection. Implement the fix. #Statamic #CMS #infosec https://www.pulsepatch.io/posts/cve-2026-27593-statamic-cms-account-takeover

    Post summary

    Statamic CMS CVE‑2026‑27593 enables account takeover through password reset link injection; a patch is available and should be applied promptly.

    0000040
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27593 Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password … https://www.cve.org/CVERecord?id=CVE-2026-27593 ----- Traducción: CVE-2026-27593 Sta… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-27593 affecting Statmatic CMS, noting a password-related vulnerability in older versions, but provides no further details or mitigation.

    0000043
    54 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27593 Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password … https://www.cve.org/CVERecord?id=CVE-2026-27593

    Post summary

    The text briefly references CVE‑2026‑27593 affecting Statmatic CMS but provides no substantive details or actionable information.

    00000159
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-27593 Password Reset Token Vulnerability in Statmatic CMS Before 6.3.3 and 5.73.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27593

    Post summary

    The text references a password reset token vulnerability in Statmatic CMS (versions before 6.3.3 and 5.73.10) but provides no details on PoC, exploit, patch, or active exploitation.

    0000040
    4.0K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Statamic CMS flaw (CVE-2026-27593) lets attackers hijack accounts via weak password recovery. Upgrade to 6.3.3/5.73.10 ASAP! 🛡️ Phishing risk — educate users & enable MFA. Details: https://radar.offseq.com/threat/cve-2026-27593-cwe-640-weak-password-recovery-mech-d... https://t.co/mZfYljD3Jc

    Post summary

    Statamic CMS vulnerability CVE-2026-27593 enables account hijacking through weak password recovery; users are urged to upgrade to 6.3.3/5.73.10, enable MFA, and educate staff.

    0000054
    269 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27593** pertains to a security flaw in **Statamic**, a CMS built on Laravel and Git. The vulnerability exists in the password reset functionality prior to versions **6.3.3** and **5.73.10**. An attacker with knowledge of a valid user's email address can exploit this flaw to **capture the password reset token** sent via email and **reset the user's password without their consent**. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27593

    Post summary

    The post announces CVE‑2026‑27593, detailing a flaw in Statamic’s password reset that lets attackers capture reset tokens and reset passwords, but it does not mention a PoC, exploit, patch, or active exploitation.

    0000055
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstatamicstatamic---

Explore more