CVE-2026-71293
EUVD-2026-5337805.08.2026, 13:24
Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case for the handle that returns the user's raw two-factor recovery codes with no access restriction.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| statamic | statamic | 𝑥 ≤ 6.23.0 | CNA |
Common Weakness Enumeration