A vulnerability labeled as problematic has been found in Statamic cms up to 5.74.0/6.23.x. Impacted is an unknown function of the component User Creation Wizard. The manipulation results in permission issues.

This vulnerability is identified as CVE-2026-64664. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.