CVE-2026-54244
LOWStatamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors
Title source: cnaDescription
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Controllers/CP/PreviewController.php only checked view authorization, but it accepts and renders caller-supplied field values. A Control Panel user with view but not edit permission could therefore submit content they were not authorized to author and generate a shareable Live Preview URL rendering it. This issue is fixed in versions 5.74.0 and 6.20.3.
References (5)
Core 5
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/statamic/cms/security/advisories/GHSA-7mqq-4v55-88gh
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/pull/14791
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/commit/87b9998f4d9e40de53346402ccf6eb3c17ba168f
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/releases/tag/v5.74.0
X_Refsource_Misc x_refsource_misc
https://github.com/statamic/cms/releases/tag/v6.20.3
Scores
CVSS v3
3.5
EPSS
0.0017
EPSS Percentile
7.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (2)
statamic/cms
< 5.74.0
statamic/cms
>= 6.0.0, < 6.20.3
Published
Jul 17, 2026
Tracked Since
Jul 18, 2026