
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28425 is a server-side template injection (code injection) vulnerability in Statamic CMS that allows authenticated control panel users with access to Antlers-enabled inputs to achieve remote code execution (RCE) in the application context. It affects Statamic versions prior to 5.73.16 (v5 branch) and prior to 6.7.2 (v6 branch, including 6.0.0-alpha.1 through 6.7.1). The vulnerability was published on February 27, 2026, by Statamic maintainer jasonvarga, with credits to researchers Neosprings and Analyst offset. It carries a CVSS v3.1 base score of 8.0 (High) (GitHub Advisory, Statamic Advisory).
The root cause is improper control of code generation (CWE-94) within Statamic's Antlers templating engine, which fails to adequately neutralize user-controlled input before evaluating it as template code. Exploitation occurs when an authenticated control panel user injects malicious Antlers template syntax into fields where Antlers processing is explicitly enabled — such as content fields with Antlers toggled on, Forms email notification settings, or third-party addon fields (e.g., SEO Pro). The attacker must have the relevant control panel permissions to configure fields or edit entries, and some user interaction is required. Notably, the initial fixes in versions 5.73.11 and 6.4.0 were found to be insufficient via a follow-up report, necessitating the subsequent patches in 5.73.16 and 6.7.2 (GitHub Advisory, Statamic Advisory).
Successful exploitation can lead to full compromise of the Statamic application, including unauthorized access to sensitive configuration data, modification or exfiltration of stored content and credentials, and potential disruption of availability. Because Statamic is a Laravel-based CMS often used to manage web content and sensitive site configurations, a compromised instance could expose database credentials, API keys, and user data. The attack is constrained to authenticated users with specific control panel permissions, limiting the blast radius to insider threats or scenarios where attacker-controlled accounts have been established (GitHub Advisory, Statamic Advisory).
As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.188% (41st percentile), indicating a relatively low near-term exploitation probability. No threat actor attribution has been reported. Exploitation requires authenticated access with specific control panel permissions, which meaningfully reduces the attack surface compared to unauthenticated vulnerabilities.
{{ }} delimiters; a payload targeting PHP code execution might leverage Antlers tags or variables that invoke underlying PHP functionality.storage/logs/laravel.log) showing unexpected PHP errors or exceptions originating from the Antlers template parser; access logs with POST requests to control panel entry edit or form configuration endpoints containing unusual {{ }} template syntax in request bodies.public/ directory or storage/ directory; modifications to .env or config files by the web server process; new files in content/ directories with embedded Antlers payloads.bash, curl, wget, python, nc) visible in process listings.Statamic has released definitive patches in versions 5.73.16 (v5 branch) and 6.7.2 (v6 branch); all users should upgrade immediately, as the earlier fixes in 5.73.11 and 6.4.0 were found to be insufficient. Users of third-party addons that depend on Statamic (e.g., SEO Pro) must verify they are running a patched Statamic version after updating their addons. As interim hardening measures, restrict control panel access and field configuration permissions strictly to trusted administrators, audit blueprint configurations to identify fields with Antlers explicitly enabled, and apply the principle of least privilege for all control panel roles (GitHub Advisory, Statamic Advisory).
The advisory was published by Statamic maintainer jasonvarga on February 27, 2026, with credits to researchers Neosprings and Analyst offset for discovery and reporting. Social media activity was observed on Bluesky and Mastodon shortly after disclosure, with automated CVE tracking accounts amplifying the advisory. No major independent security researcher commentary or media coverage beyond standard vulnerability aggregation sites has been identified at this time (Statamic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."