Content Management System Vulnerability in Statamic by Statamic
CVE-2026-64662

6.5MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64662?

In Statamic, prior versions 5.74.1 and 6.24.0, an access control issue allows authenticated Control Panel users to access content entries without proper permissions. This vulnerability could expose sensitive data, including unpublished entries and custom field values, through the navigation endpoint. This critical flaw highlights the importance of ensuring that user permissions are strictly enforced, and it has been addressed in subsequent releases.

Affected Version(s)

cms < 5.74.1 < 5.74.1

cms >= 6.0.0, < 6.24.0 < 6.0.0, 6.24.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.