CVE-2026-49288

MEDIUM

Statamic CMS < 5.73.23 and 6.x < 6.20.0 - Control Panel Resource Disclosure

Title source: manual
STIX 2.1

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. Depending on the resource, this could expose titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. No data could be modified. This has been fixed in 5.73.23 and 6.20.0.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0027
EPSS Percentile 19.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-862 CWE-863
Status published
Products (4)
statamic/cms 0 - 5.73.23Packagist
statamic/cms 6.0.0 - 6.20.0Packagist
statamic/cms < 5.73.23
statamic/cms >= 6.0.0, < 6.20.0
Published Jun 19, 2026
Tracked Since Jun 20, 2026