CVE-2026-64662
Received Received - Intake

Information Disclosure in Statamic CMS

Vulnerability report for CVE-2026-64662, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: GitHub, Inc.

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
statamic statamic to 6.24.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Statamic allows an authenticated user with Control Panel access to view content from entries they do not have permission to access. This includes content and custom field values from any collection, even unpublished entries, through the navigation endpoint. The attacker cannot modify any data.

Detection Guidance

To detect this vulnerability, check the version of Statamic installed on your system. Compare it against versions 5.74.1 and 6.24.0. If your version is below these, the system is vulnerable. Use commands like 'composer show statamic/statamic' or check the version in the Statamic control panel.

Impact Analysis

If you use Statamic versions before 5.74.1 or 6.24.0, an attacker with Control Panel access could view sensitive or restricted content without permission. This may lead to unauthorized data exposure, privacy breaches, or compliance violations depending on the content accessed.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face legal penalties, reputational damage, and loss of customer trust if such breaches occur.

Mitigation Strategies

Immediately update Statamic to version 5.74.1 or 6.24.0 or later. Ensure all authenticated users have the least privileges necessary. Review access logs for suspicious activity related to the navigation endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64662. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart