CVE-2026-27939

HIGH

Statmatic 6.0.0-6.3.9 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. This has been fixed in 6.4.0.

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 5.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (2)
statamic/cms 6.0.0 - 6.4.0Packagist
statamic/statamic 6.0.0 - 6.4.0
Published Feb 27, 2026
Tracked Since Feb 28, 2026