CVE-2026-44306Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an account existed for a given email address. An unauthenticated attacker could use this to enumerate valid users, which can aid in follow-up credential-based attacks. This vulnerability is fixed in 5.73.21 and 6.15.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-204

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-07); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-07: 1Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-06-27: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-06-27: 105-0705-1205-1306-27
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-071
Disclosure1
2026-05-121
Disclosure1
2026-05-131
Disclosure1
2026-06-271
General1
Full discourse4 posts
  • DailyCVE@dailycve
    General

    🟠 Statamic CMS, CSV Formula Injection, #CVE-2026-44306 (Moderate) -DC-Jun2026-722 https://dailycve.com/statamic-cms-csv-formula-injection-cve-2026-44306-moderate-dc-jun2026-722/

    Post summary

    This brief statement announces the Statamic CMS CSV Formula Injection vulnerability CVE‑2026‑44306, noting a moderate severity, but does not provide PoC, exploit tools, active exploitation evidence, or patch information.

    0000062
    216 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44306 User Enumeration via Forgot Password Response in Statamic Before 5.73.21 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44306

    Post summary

    The brief notice discloses CVE-2026-44306 as a user‑enumeration flaw in Statamic before v5.73.21, without providing any PoC, exploit code, or patch information.

    0000074
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44306 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the forgot password forms hinted at whether an acco… https://www.cve.org/CVERecord?id=CVE-2026-44306

    Post summary

    This post announces CVE-2026-44306, noting that before Statamic versions 5.73.21 and 6.15.0, the forgot‑password feature exposed account existence through its responses.

    00000107
    57.5K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Statamic CMS, Email Enumeration, #CVE-2026-44306 (Moderate) https://dailycve.com/statamic-cms-email-enumeration-cve-2026-44306-moderate/

    Post summary

    A moderate‑severity CVE‑2026‑44306 affecting Statamic CMS allows attackers to enumerate email addresses; no PoC, exploit, or active exploitation evidence is mentioned.

    0000031
    196 followersView on X

Explore more