CVE-2026-64662

MEDIUM

Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

Title source: cna
STIX 2.1

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.

References (5)

Core 5

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 22.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-862
Status published
Products (4)
statamic/cms 0 - 5.74.1Packagist
statamic/cms 6.0.0 - 6.24.0Packagist
statamic/cms < 5.74.1
statamic/cms >= 6.0.0, < 6.24.0
Published Aug 06, 2026
Tracked Since Aug 07, 2026