CVE-2026-27939

HIGH

Statmatic 6.0.0-6.3.9 - Privilege Escalation

Title source: llm

Description

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. This has been fixed in 6.4.0.

Scores

CVSS v3 8.8
EPSS 0.0001
EPSS Percentile 2.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-287
Status published

Affected Products (2)

statamic/cms < 6.4.0Packagist
statamic/statamic < 6.4.0

Timeline

Published Feb 27, 2026
Tracked Since Feb 28, 2026