What is CVE-2026-71293?
The AugmentedUser::get() function in Statamic CMS returns raw two-factor recovery codes for the `two_factor_recovery_codes` handle without any access restrictions. This flaw may allow unauthorized or low-privileged users to access sensitive recovery information. Immediate upgrade to the patched version and review of exposed codes are recommended.
Azərbaycanca: Statamic CMS-də AugmentedUser::get() funksiyası `two_factor_recovery_codes` üçün heç bir giriş məhdudiyyəti olmadan istifadəçinin xam iki faktorlu bərpa kodlarını qaytarır. Bu zəiflik autentifikasiya olunmamış və ya aşağı səviyyəli istifadəçilərə həssas məlumatlara çıxış əldə etməyə imkan verə bilər. Təhlükəsizlik tədbiri olaraq, dərhal ən son versiyaya yenilənməli və kodların məruz qalma riski qiymətləndirilməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
In which function does CVE-2026-71293 vulnerability exist in Statamic CMS?
The vulnerability is in the AugmentedUser::get() function.
What sensitive data can be exposed by exploiting CVE-2026-71293?
It may expose the user's raw two-factor recovery codes (`two_factor_recovery_codes`).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.