CVE-2026-28423: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-28423 is a Server-Side Request Forgery (SSRF) vulnerability in Statamic CMS, a Laravel and Git-powered content management system. When the Glide image manipulation feature is configured in insecure mode (a non-default setting), an unauthenticated attacker can abuse the image proxy to force the server to send HTTP requests to arbitrary URLs — either via direct URL manipulation or through the watermark feature. Affected versions include all Statamic releases prior to 5.73.11 (5.x branch) and 6.0.0 through 6.3.x (6.x branch, fixed in 6.4.0). The vulnerability was disclosed on February 27, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 6.8 (Moderate) per the GitHub Security Advisory, though Feedly's data notes an alternative score of 8.6 based on a slightly different vector (GitHub Advisory, Statamic Advisory).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), where the Glide image proxy fails to sufficiently validate or restrict the destination URLs it fetches when operating in insecure mode. In this non-default configuration, the image proxy accepts externally supplied URLs — either as direct image source parameters or as watermark URLs — without adequate allowlist enforcement, enabling the server to be directed to make outbound HTTP requests to attacker-controlled destinations. The fix, implemented via the "External Glide URL validation" change (PR #14101 by @jasonvarga), adds proper URL validation to restrict which external hosts the proxy may contact. The vulnerability requires no privileges and no user interaction, but exploitation is contingent on the administrator having explicitly enabled insecure mode for Glide (GitHub Advisory, v5.73.11 Release).

Impact

Successful exploitation allows an unauthenticated attacker to leverage the Statamic server as a proxy to reach internal network services, cloud metadata endpoints (e.g., AWS IMDSv1 at 169.254.169.254), and other hosts accessible from the server's network context. The primary impact is a high confidentiality loss — sensitive data such as cloud credentials, internal API tokens, and configuration details can be exfiltrated — while integrity and availability are not directly affected. This SSRF can facilitate lateral movement into internal infrastructure or enable privilege escalation by harvesting cloud IAM credentials from metadata services (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.025% (7th percentile), indicating a low near-term exploitation probability. Exploitation is further constrained by the requirement that the target Statamic instance must have Glide configured in insecure mode, which is not the default configuration (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible Statamic CMS instances running versions prior to 5.73.11 or 6.4.0 using web fingerprinting tools (e.g., Wappalyzer, Shodan, or HTTP response headers).
  2. Verify insecure mode: Confirm that Glide image manipulation is enabled in insecure mode by attempting to access the Glide image proxy endpoint (typically /img) with an external URL parameter — a successful image fetch or HTTP response indicates the vulnerable configuration is active.
  3. Craft SSRF payload via direct URL: Send a crafted request to the Glide proxy endpoint supplying an internal or metadata URL as the image source, e.g., GET /img?src=http://169.254.169.254/latest/meta-data/iam/security-credentials/ to probe cloud metadata services.
  4. Craft SSRF payload via watermark feature: Alternatively, supply the target internal URL as a watermark parameter in the Glide image manipulation request, which triggers a server-side HTTP fetch to the attacker-specified URL.
  5. Harvest response data: Analyze the server's response or use an out-of-band HTTP listener (e.g., Burp Collaborator, interactsh) to capture data returned from internal services, including credentials, tokens, or configuration details (GitHub Advisory, Statamic Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the Statamic/web server process to internal RFC-1918 addresses (e.g., 10.x.x.x, 172.16.x.x, 192.168.x.x) or cloud metadata IPs (169.254.169.254, fd00:ec2::254); unexpected DNS lookups or HTTP connections to attacker-controlled external hosts originating from the web server.
  • Logs: Web server access logs showing requests to the Glide image proxy endpoint (/img) with external or internal URLs as src or watermark parameters; repeated or automated requests to the image proxy with varying URL targets.
  • Application Logs: Laravel/Statamic application logs recording HTTP client requests to unusual or internal destinations initiated by the Glide image processing pipeline.
  • Process: Unusual outbound network connections from the PHP-FPM or web server process to non-standard destinations, detectable via netstat, ss, or endpoint detection tools.

Mitigation and workarounds

Statamic has released patched versions 5.73.11 (for the 5.x branch) and 6.4.0 (for the 6.x branch), both published on February 27, 2026, which include external Glide URL validation to restrict arbitrary outbound requests (v5.73.11 Release, v6.4.0 Release). As an immediate workaround, administrators should disable Glide insecure mode or revert to the default secure configuration if the feature is not required. Additionally, network-level controls — such as firewall rules blocking the web server from reaching internal services and cloud metadata endpoints — can significantly reduce the exploitability and impact of this vulnerability (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher dxlerYT and disclosed by Statamic maintainer jasonvarga via the GitHub Security Advisory program on February 27, 2026 (Statamic Advisory). No significant broader media coverage or notable community commentary beyond the standard advisory tracking has been identified at this time.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management