CVE-2026-49288
Last modified
CVE-2026-49288 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Control Panel user could view metadata and content for resources they don't have permission to view, including entries, assets, users, roles, groups, and other configured resources. Depending on the resource, this could expose titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups. No data could be modified. This has been fixed in 5.73.23 and 6.20.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-49288?
How severe is CVE-2026-49288?
How do I fix CVE-2026-49288?
Are you affected by CVE-2026-49288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
