CVE-2026-71293

Summary

Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case for the handle that returns the user's raw two-factor recovery codes with no access restriction.

Affected Software

VendorProductVersion RangeStatus
statamiccms0 <= 6.23.0affected

Weaknesses

  • CWE-200: CWE-200

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References