Unauthorized Access Flaw in Statamic CMS by Statamic
CVE-2026-49288

4.3MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
19 June 2026

What is CVE-2026-49288?

Statamic, a popular content management system built on Laravel and Git, has a vulnerability that allows authenticated Control Panel users to access metadata and content for resources without appropriate permissions. This flaw affects versions prior to 5.73.23 and 6.20.0 and can potentially expose sensitive information such as titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. Users are advised to update to the fixed versions to mitigate this risk.

Affected Version(s)

cms < 5.73.23 < 5.73.23

cms >= 6.0.0, < 6.20.0 < 6.0.0, 6.20.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.