File Access Vulnerability in Statamic CMS by Statamic
CVE-2026-33171
4.3MEDIUM
What is CVE-2026-33171?
Statamic, a Laravel and Git powered content management system, has a vulnerability that allows authenticated Control Panel users to access arbitrary .json, .yaml, and .csv files stored on the server by manipulating the filename parameter in the fieldtype's endpoint. This issue is present in versions prior to 5.73.14 and 6.7.0, and it poses a risk of unauthorized data exposure, potentially compromising sensitive information.
Affected Version(s)
cms >= 6.0.0-alpha.1, < 6.7.0 < 6.0.0-alpha.1, 6.7.0
cms < 5.73.14 < 5.73.14
