Content Management System Vulnerability in Statamic by Statamic
CVE-2026-64662
6.5MEDIUM
What is CVE-2026-64662?
In Statamic, prior versions 5.74.1 and 6.24.0, an access control issue allows authenticated Control Panel users to access content entries without proper permissions. This vulnerability could expose sensitive data, including unpublished entries and custom field values, through the navigation endpoint. This critical flaw highlights the importance of ensuring that user permissions are strictly enforced, and it has been addressed in subsequent releases.
Affected Version(s)
cms < 5.74.1 < 5.74.1
cms >= 6.0.0, < 6.24.0 < 6.0.0, 6.24.0
