Authorization Bypass in Statamic CMS by Statamic
CVE-2026-33887

5.4MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33887?

Statamic, a content management system powered by Laravel and Git, is susceptible to an authorization bypass flaw. This issue allows authenticated Control Panel users to access entry revisions across any collection with revisions activated, irrespective of their granted collection permissions. As a result, sensitive entry field values and blueprint data may be exposed. Additionally, it enables users to create entry revisions without possessing edit permissions; however, this action merely captures the current content state, leaving published content unaffected. This vulnerability has been addressed in versions 5.73.16 and 6.7.2.

Affected Version(s)

cms < 5.73.16 < 5.73.16

cms >= 6.0.0-alpha.1, < 6.7.2 < 6.0.0-alpha.1, 6.7.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.