CVE-2026-25759: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-25759 is a stored cross-site scripting (XSS) vulnerability in Statamic CMS that enables privilege escalation by allowing authenticated users with content creation permissions to inject malicious JavaScript into content titles. The injected script executes in the browser of any higher-privileged user — including super administrators — who views the affected content, potentially enabling unauthorized super admin account creation. It affects Statamic CMS versions 6.0.0 through 6.2.2 (Composer package statamic/cms) and was disclosed on February 11, 2026, with a patch released in version 6.2.3. The vulnerability carries a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, Statamic Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in Statamic's command palette component (CommandPalette.vue). Content titles were rendered without HTML escaping in the command palette's fuzzy-search result highlighting logic, allowing raw HTML/JavaScript to be injected and later rendered as live DOM content when a privileged user opened the command palette. The fix, committed in 6ed4f65, introduced an escapeHtml() call via a new highlightResult() function that sanitizes text before passing it to fuzzysort's highlight renderer, preventing script injection (Statamic Commit, GitHub Advisory). Exploitation requires the attacker to hold a valid account with control panel access and content creation permissions, and a higher-privileged user must subsequently interact with the command palette while the malicious content title is present (Statamic Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser session of a higher-privileged user, including super administrators, resulting in high confidentiality and integrity impact with no availability impact. The most severe consequence is unauthorized creation of super admin accounts, effectively granting the attacker full administrative control over the Statamic CMS instance. Additional risks include session hijacking, credential theft, and exfiltration of sensitive data accessible to the compromised administrator (GitHub Advisory, Statamic Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is approximately 0.009–0.013%, placing it in the 2nd percentile for near-term exploitation likelihood (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported; the vulnerability was discovered and reported by a researcher credited as "Neosprings" (Statamic Advisory).

Exploitation steps

  1. Gain access: Obtain or register an account on the target Statamic CMS instance (versions 6.0.0–6.2.2) with control panel access and content creation permissions.
  2. Craft malicious content title: Create or edit a content entry (e.g., a page, collection entry, or asset) and set its title to a JavaScript payload, such as <img src=x onerror="fetch('/cp/users',{method:'POST',body:JSON.stringify({name:'attacker',email:'attacker@evil.com',super:true,password:'P@ssw0rd!',password_confirmation:'P@ssw0rd!'}),headers:{'Content-Type':'application/json','X-CSRF-TOKEN':document.querySelector('meta[name=csrf-token]').content}})">.
  3. Wait for privileged user interaction: The injected title is stored in the CMS. When a higher-privileged user (e.g., super admin) opens the command palette and the malicious content title appears in search results, the unescaped HTML is rendered by the fuzzysort highlight function, triggering script execution.
  4. Achieve privilege escalation: The executed JavaScript runs in the admin's browser session with their privileges, enabling actions such as creating a new super admin account, exfiltrating session tokens, or performing other administrative operations on behalf of the victim (Statamic Advisory, Statamic Commit).

Indicators of compromise

  • Logs: Statamic/Laravel access logs showing unexpected POST requests to user creation or administrative endpoints (e.g., /cp/users) originating from a super admin session shortly after command palette usage; unusual admin account creation events in application audit logs.
  • File System / Database: Presence of newly created super admin user accounts not provisioned through normal administrative workflows; content entries with titles containing HTML tags or JavaScript syntax (e.g., <script>, onerror=, javascript:).
  • Network: Outbound HTTP requests from the CMS server or admin browser to unknown external domains, potentially carrying exfiltrated session tokens or credentials.
  • Application Behavior: Unexpected changes to user roles or permissions, particularly elevation to super admin status for accounts that should not have it (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Statamic CMS to version 6.2.3 or later, which escapes HTML in command palette content titles before rendering (Statamic Release, GitHub Advisory). As interim measures, administrators should restrict control panel and content creation access to only fully trusted users, audit existing content entries for titles containing HTML or JavaScript, and implement a strict Content Security Policy (CSP) to limit the impact of any XSS execution. Monitoring for unexpected super admin account creation is also recommended until patching is complete (Feedly).

Community reactions

The vulnerability was reported by a researcher credited as "Neosprings" and published by Statamic maintainer jasonvarga on February 11, 2026. Coverage appeared on security aggregation sites including The Hacker Wire and Infinitsec shortly after disclosure, with community discussion noting the privilege escalation potential as particularly impactful for multi-user Statamic deployments (Feedly).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management