Authorization Bypass in Statamic CMS by Statamic
CVE-2026-33887
5.4MEDIUM
What is CVE-2026-33887?
Statamic, a content management system powered by Laravel and Git, is susceptible to an authorization bypass flaw. This issue allows authenticated Control Panel users to access entry revisions across any collection with revisions activated, irrespective of their granted collection permissions. As a result, sensitive entry field values and blueprint data may be exposed. Additionally, it enables users to create entry revisions without possessing edit permissions; however, this action merely captures the current content state, leaving published content unaffected. This vulnerability has been addressed in versions 5.73.16 and 6.7.2.
Affected Version(s)
cms < 5.73.16 < 5.73.16
cms >= 6.0.0-alpha.1, < 6.7.2 < 6.0.0-alpha.1, 6.7.2
