
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32612 is a stored cross-site scripting (XSS) vulnerability in Statamic CMS, a Laravel and Git-powered content management system, classified as "Privilege escalation via stored cross-site scripting." It affects Statamic versions 6.0.0 through 6.6.1 (prior to 6.6.2) and was published on March 12, 2026, by researcher Shirsendu Mondal (Shirshaw64p) via responsible disclosure. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Statamic Advisory).
The root cause (CWE-79) is improper neutralization of user-controlled input in the Control Panel's color mode preference field. User preference data submitted via POST /cp/preferences/js is stored without validation and later rendered into inline JavaScript using Blade's unsafe raw output directive ({!! !!}), as in: let mode = {!! ($userMode = $user?->preferredColorMode()) ? "'" . $userMode . "'" : 'null' !!};. Because the value is not encoded, an attacker can inject a payload such as ';window.XSS_POC_1337=1;// to break out of the string context and execute arbitrary JavaScript. Exploitation requires the attacker to hold a low-privileged Control Panel account and relies on a higher-privileged administrator using Statamic's built-in user impersonation feature to trigger execution (Shirshaw64p PoC, Statamic Advisory).
Successful exploitation allows attacker-controlled JavaScript to execute within an administrator's browser session when that administrator impersonates the attacker's account. This can result in administrative action forgery, session token theft, unauthorized configuration changes, and effective privilege escalation from a low-privileged CP user to administrator-level access. There is no direct server-side compromise, and availability is not impacted, but confidentiality and integrity of the administrator session are at risk (Shirshaw64p PoC, GitHub Advisory).
A public proof-of-concept (PoC) with detailed reproduction steps is available on GitHub, including the specific endpoint, payload, and attack scenario (Shirshaw64p PoC). The EPSS score is approximately 0.016% (4th percentile), indicating a low but non-zero probability of exploitation in the wild within 30 days. There is currently no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
POST /cp/preferences/js.POST /cp/preferences/js with the color_mode preference value set to a JavaScript injection payload, e.g., ';window.XSS_POC_1337=1;//. This value is stored server-side without sanitization./cp/preferences/js containing JavaScript syntax characters (e.g., single quotes, semicolons, window., document.cookie) in preference value fields./cp/preferences/js with anomalous or non-standard color_mode values; administrator impersonation events in Statamic audit logs shortly followed by unexpected outbound requests from the admin browser.color_mode field.Upgrade Statamic CMS to version 6.6.2 or later, which addresses the vulnerability by implementing strict allowlist validation of preference values, safe JSON encoding for output, and avoiding raw Blade output ({!! !!}) for user-controlled data. As a workaround prior to patching, restrict Control Panel access to trusted users only and disable or limit use of the administrator impersonation feature. Monitoring preference fields for unexpected JavaScript content can provide additional detection coverage (Statamic Advisory, GitHub Advisory).
The vulnerability was responsibly disclosed by researcher Shirsendu Mondal (Shirshaw64p) of UNC Pembroke, and the Statamic security team acknowledged and patched the issue promptly in version 6.6.2. The advisory was published by Statamic maintainer jasonvarga on March 12, 2026, following coordinated disclosure practices. Coverage appeared on several CVE tracking and threat intelligence platforms shortly after disclosure, with no significant controversy or widespread community discussion noted (Statamic Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."