Data Exposure Vulnerability in Statamic CMS
CVE-2026-33882

6.5MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33882?

Statamic, a content management system built on Laravel and Git, was found to have a vulnerability that allowed the markdown preview endpoint to be exploited. This flaw permitted authenticated control panel users to manipulate the endpoint to access sensitive information from arbitrary fieldtypes. Specifically, the users fieldtype was affected, leading to potential exposure of sensitive user data including email addresses and encrypted authentication credentials. This issue has been addressed in the updates 5.73.16 and 6.7.2, which mitigate the risks associated with this vulnerability.

Affected Version(s)

cms < 5.73.16 < 5.73.16

cms >= 6.0.0-alpha.1, < 6.7.2 < 6.0.0-alpha.1, 6.7.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.