CVE-2026-49288
Received Received - Intake
Information Disclosure in Statamic CMS

Publication date: 2026-06-19

Last updated on: 2026-06-19

Assigner: GitHub, Inc.

Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. Depending on the resource, this could expose titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. No data could be modified. This has been fixed in 5.73.23 and 6.20.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-19
Last Modified
2026-06-19
Generated
2026-06-21
AI Q&A
2026-06-19
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
statamic cms to 5.73.23|end_excluding=6.20.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization issue in the Control Panel fieldtype endpoints of Statamic CMS. It allows an authenticated user to view metadata and content of resources they do not have permission to access. These resources include entries, assets, users, roles, groups, and other configured resources.

The exposed information can include titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. However, no data modification is possible through this vulnerability.

The issue affects Statamic CMS versions prior to 5.73.23 and 6.20.0, where the fix has been applied.

Impact Analysis

This vulnerability can impact you by exposing sensitive information that you may expect to be restricted. An authenticated user with low privileges can access metadata and content of restricted resources without proper authorization.

The exposed data includes titles, custom field values, entry content, asset metadata, and information about users, roles, and groups. This could lead to information disclosure risks, potentially aiding attackers or unauthorized users in gathering intelligence about your system.

However, the vulnerability does not allow modification or deletion of data, limiting the impact to information exposure only.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade Statamic CMS to version 5.73.23 or later, or 6.20.0 or later, as these versions contain the fix for the missing authorization issue.

Ensure that only authenticated users with appropriate permissions have access to the Control Panel to reduce exposure risk.

Compliance Impact

This vulnerability allows authenticated users to view metadata and content of restricted resources they do not have permission to access, potentially exposing sensitive information such as titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups.

Such unauthorized exposure of sensitive information could lead to non-compliance with data protection regulations and standards like GDPR and HIPAA, which require strict access controls and protection of personal and sensitive data.

However, no data modification is possible through this vulnerability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49288. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart