
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28424 is a missing authorization vulnerability in Statamic CMS (a Laravel and Git-powered content management system) that allows authenticated low-privileged control panel users to access user email addresses they are not permitted to view. The flaw exists in the user fieldtype's data endpoint, which incorrectly included email addresses in responses regardless of whether the requesting user held the "view users" permission. It affects all Statamic versions prior to 5.73.11 (5.x branch) and versions 6.0.0 through 6.4.0 (6.x branch). Disclosed on February 27, 2026, it carries a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Statamic Advisory).
The root cause is classified as CWE-862 (Missing Authorization): the user fieldtype's data endpoint failed to enforce the "view users" permission check before including email addresses in its API responses. An authenticated attacker with any level of control panel access — even without the "view users" permission — could query this endpoint over the network to retrieve email addresses of all users registered in the Statamic instance. No complex attack chain or user interaction is required; the only precondition is possession of valid (low-privilege) control panel credentials (Github Advisory, Statamic Advisory).
Successful exploitation results in unauthorized disclosure of user email addresses, representing a high confidentiality impact with no effect on integrity or availability. An attacker who harvests these email addresses could use them to conduct targeted phishing campaigns, social engineering attacks, or credential stuffing attempts against affected users. While the vulnerability does not directly enable lateral movement or system compromise, the exposed contact information can serve as a stepping stone for further attacks against the Statamic instance's user base (Github Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.042% (13th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access to the Statamic control panel, which limits the attacker pool but does not eliminate risk in multi-tenant or shared-access deployments (Github Advisory).
Statamic has released patched versions addressing this vulnerability: 5.73.11 for the 5.x branch and 6.4.0 for the 6.x branch. Users should upgrade immediately to one of these versions. No configuration-based workaround is available; upgrading is the only remediation. As a supplementary measure, administrators should audit control panel user permissions to ensure the principle of least privilege is applied, and review access logs to determine whether the vulnerable endpoint was queried by low-privileged users prior to patching (Statamic Advisory, v5.73.11 Release, v6.4.0 Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."