CVE-2026-25633

MEDIUM

Statamic Cms < 5.73.6 - Missing Authorization

Title source: rule
STIX 2.1

Description

Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.

Scores

CVSS v3 4.3
EPSS 0.0001
EPSS Percentile 2.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
statamic/cms 0 - 5.73.6Packagist
statamic/statamic < 5.73.6
Published Feb 11, 2026
Tracked Since Feb 18, 2026