CVE-2026-28424: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-28424 is a missing authorization vulnerability in Statamic CMS (a Laravel and Git-powered content management system) that allows authenticated low-privileged control panel users to access user email addresses they are not permitted to view. The flaw exists in the user fieldtype's data endpoint, which incorrectly included email addresses in responses regardless of whether the requesting user held the "view users" permission. It affects all Statamic versions prior to 5.73.11 (5.x branch) and versions 6.0.0 through 6.4.0 (6.x branch). Disclosed on February 27, 2026, it carries a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Statamic Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the user fieldtype's data endpoint failed to enforce the "view users" permission check before including email addresses in its API responses. An authenticated attacker with any level of control panel access — even without the "view users" permission — could query this endpoint over the network to retrieve email addresses of all users registered in the Statamic instance. No complex attack chain or user interaction is required; the only precondition is possession of valid (low-privilege) control panel credentials (Github Advisory, Statamic Advisory).

Impact

Successful exploitation results in unauthorized disclosure of user email addresses, representing a high confidentiality impact with no effect on integrity or availability. An attacker who harvests these email addresses could use them to conduct targeted phishing campaigns, social engineering attacks, or credential stuffing attempts against affected users. While the vulnerability does not directly enable lateral movement or system compromise, the exposed contact information can serve as a stepping stone for further attacks against the Statamic instance's user base (Github Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is approximately 0.042% (13th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access to the Statamic control panel, which limits the attacker pool but does not eliminate risk in multi-tenant or shared-access deployments (Github Advisory).

Exploitation steps

  1. Obtain control panel access: Acquire any valid low-privilege Statamic control panel account (e.g., an editor or contributor role without the "view users" permission).
  2. Identify the user fieldtype data endpoint: Locate the API endpoint used by the user fieldtype to fetch user data within the Statamic control panel (typically accessible via the CMS's internal REST-like API routes).
  3. Send authenticated request: Issue an authenticated HTTP GET request to the user fieldtype's data endpoint using the low-privilege session token or credentials.
  4. Harvest email addresses: Parse the JSON response, which incorrectly includes user email addresses despite the requesting account lacking the "view users" permission.
  5. Leverage harvested data: Use the collected email addresses for phishing, social engineering, or credential stuffing attacks against the Statamic instance's users (Github Advisory).

Indicators of compromise

  • Logs: Statamic/Laravel access logs showing repeated or unusual GET requests to the user fieldtype data endpoint from accounts that do not hold the "view users" permission; look for low-privilege user sessions querying user-related API routes.
  • Network: Unexpected API calls to internal Statamic user fieldtype endpoints originating from authenticated sessions with limited roles, particularly if accessed in bulk or at unusual hours.
  • Application Logs: Laravel application logs recording access to user data endpoints by accounts without appropriate permissions, which may surface as anomalous authorization events if logging is verbose.

Mitigation and workarounds

Statamic has released patched versions addressing this vulnerability: 5.73.11 for the 5.x branch and 6.4.0 for the 6.x branch. Users should upgrade immediately to one of these versions. No configuration-based workaround is available; upgrading is the only remediation. As a supplementary measure, administrators should audit control panel user permissions to ensure the principle of least privilege is applied, and review access logs to determine whether the vulnerable endpoint was queried by low-privileged users prior to patching (Statamic Advisory, v5.73.11 Release, v6.4.0 Release).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management