CVE-2026-64662 Details
Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.
A vulnerability exists in Statamic CMS versions prior to 5.74.1 and 6.24.0, allowing authenticated Control Panel users to access content from entries they were not authorized to view. This includes entry details and custom field values from any collection, as well as unpublished entries, through the navigation endpoint. Although the vulnerability enables unauthorized data access, it does not allow for any modifications. The issue has been resolved in versions 5.74.1 and 6.24.0.
Users can upgrade to Statamic CMS versions 5.74.1 or 6.24.0 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/statamic/cms/commit/6557f1d8a0d61c0e7ad9c9a8f42cb3288607495d | [email protected] | Source CodeVendor |
| https://github.com/statamic/cms/pull/14906 | [email protected] | Issue TrackingVendor |
| https://github.com/statamic/cms/releases/tag/v5.74.1 | [email protected] | Release NotesVendor |
| https://github.com/statamic/cms/releases/tag/v6.24.0 | [email protected] | Release NotesVendor |
| https://github.com/statamic/cms/security/advisories/GHSA-qh8c-7588-qfrv | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Statamic | < 5.74.1 (semver) < 6.24.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion