CVE-2026-28425: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-28425 is a server-side template injection (code injection) vulnerability in Statamic CMS that allows authenticated control panel users with access to Antlers-enabled inputs to achieve remote code execution (RCE) in the application context. It affects Statamic versions prior to 5.73.16 (v5 branch) and prior to 6.7.2 (v6 branch, including 6.0.0-alpha.1 through 6.7.1). The vulnerability was published on February 27, 2026, by Statamic maintainer jasonvarga, with credits to researchers Neosprings and Analyst offset. It carries a CVSS v3.1 base score of 8.0 (High) (GitHub Advisory, Statamic Advisory).

Technical details

The root cause is improper control of code generation (CWE-94) within Statamic's Antlers templating engine, which fails to adequately neutralize user-controlled input before evaluating it as template code. Exploitation occurs when an authenticated control panel user injects malicious Antlers template syntax into fields where Antlers processing is explicitly enabled — such as content fields with Antlers toggled on, Forms email notification settings, or third-party addon fields (e.g., SEO Pro). The attacker must have the relevant control panel permissions to configure fields or edit entries, and some user interaction is required. Notably, the initial fixes in versions 5.73.11 and 6.4.0 were found to be insufficient via a follow-up report, necessitating the subsequent patches in 5.73.16 and 6.7.2 (GitHub Advisory, Statamic Advisory).

Impact

Successful exploitation can lead to full compromise of the Statamic application, including unauthorized access to sensitive configuration data, modification or exfiltration of stored content and credentials, and potential disruption of availability. Because Statamic is a Laravel-based CMS often used to manage web content and sensitive site configurations, a compromised instance could expose database credentials, API keys, and user data. The attack is constrained to authenticated users with specific control panel permissions, limiting the blast radius to insider threats or scenarios where attacker-controlled accounts have been established (GitHub Advisory, Statamic Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.188% (41st percentile), indicating a relatively low near-term exploitation probability. No threat actor attribution has been reported. Exploitation requires authenticated access with specific control panel permissions, which meaningfully reduces the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Gain authenticated access: Obtain or compromise a Statamic control panel account with permissions to configure fields (e.g., blueprint editor) or edit entries in a collection where Antlers is enabled on a field.
  2. Identify Antlers-enabled inputs: Navigate the control panel to locate fields explicitly configured with Antlers processing enabled, Forms email notification settings, or third-party addon fields (e.g., SEO Pro) that render Antlers templates.
  3. Inject malicious Antlers payload: Insert a crafted Antlers template expression into the vulnerable input field. Antlers syntax uses {{ }} delimiters; a payload targeting PHP code execution might leverage Antlers tags or variables that invoke underlying PHP functionality.
  4. Trigger template rendering: Save the entry or submit the form to cause the Antlers engine to evaluate the injected template content server-side.
  5. Achieve RCE: The injected template expression executes arbitrary code in the application context (as the web server/PHP process user), enabling actions such as reading environment variables, writing web shells, or establishing reverse shells for further lateral movement (GitHub Advisory, Statamic Advisory).

Indicators of compromise

  • Logs: Statamic/Laravel application logs (storage/logs/laravel.log) showing unexpected PHP errors or exceptions originating from the Antlers template parser; access logs with POST requests to control panel entry edit or form configuration endpoints containing unusual {{ }} template syntax in request bodies.
  • File System: Unexpected PHP files (web shells) written to the public/ directory or storage/ directory; modifications to .env or config files by the web server process; new files in content/ directories with embedded Antlers payloads.
  • Process: Unusual child processes spawned by the PHP-FPM or web server process (e.g., bash, curl, wget, python, nc) visible in process listings.
  • Network: Unexpected outbound connections from the web server to external IPs, particularly on non-standard ports, following control panel activity; DNS lookups for unfamiliar external domains initiated by the PHP process.

Mitigation and workarounds

Statamic has released definitive patches in versions 5.73.16 (v5 branch) and 6.7.2 (v6 branch); all users should upgrade immediately, as the earlier fixes in 5.73.11 and 6.4.0 were found to be insufficient. Users of third-party addons that depend on Statamic (e.g., SEO Pro) must verify they are running a patched Statamic version after updating their addons. As interim hardening measures, restrict control panel access and field configuration permissions strictly to trusted administrators, audit blueprint configurations to identify fields with Antlers explicitly enabled, and apply the principle of least privilege for all control panel roles (GitHub Advisory, Statamic Advisory).

Community reactions

The advisory was published by Statamic maintainer jasonvarga on February 27, 2026, with credits to researchers Neosprings and Analyst offset for discovery and reporting. Social media activity was observed on Bluesky and Mastodon shortly after disclosure, with automated CVE tracking accounts amplifying the advisory. No major independent security researcher commentary or media coverage beyond standard vulnerability aggregation sites has been identified at this time (Statamic Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management