CVE-2026-32612: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32612 is a stored cross-site scripting (XSS) vulnerability in Statamic CMS, a Laravel and Git-powered content management system, classified as "Privilege escalation via stored cross-site scripting." It affects Statamic versions 6.0.0 through 6.6.1 (prior to 6.6.2) and was published on March 12, 2026, by researcher Shirsendu Mondal (Shirshaw64p) via responsible disclosure. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Statamic Advisory).

Technical details

The root cause (CWE-79) is improper neutralization of user-controlled input in the Control Panel's color mode preference field. User preference data submitted via POST /cp/preferences/js is stored without validation and later rendered into inline JavaScript using Blade's unsafe raw output directive ({!! !!}), as in: let mode = {!! ($userMode = $user?->preferredColorMode()) ? "'" . $userMode . "'" : 'null' !!};. Because the value is not encoded, an attacker can inject a payload such as ';window.XSS_POC_1337=1;// to break out of the string context and execute arbitrary JavaScript. Exploitation requires the attacker to hold a low-privileged Control Panel account and relies on a higher-privileged administrator using Statamic's built-in user impersonation feature to trigger execution (Shirshaw64p PoC, Statamic Advisory).

Impact

Successful exploitation allows attacker-controlled JavaScript to execute within an administrator's browser session when that administrator impersonates the attacker's account. This can result in administrative action forgery, session token theft, unauthorized configuration changes, and effective privilege escalation from a low-privileged CP user to administrator-level access. There is no direct server-side compromise, and availability is not impacted, but confidentiality and integrity of the administrator session are at risk (Shirshaw64p PoC, GitHub Advisory).

Exploitability

A public proof-of-concept (PoC) with detailed reproduction steps is available on GitHub, including the specific endpoint, payload, and attack scenario (Shirshaw64p PoC). The EPSS score is approximately 0.016% (4th percentile), indicating a low but non-zero probability of exploitation in the wild within 30 days. There is currently no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Gain low-privileged access: Obtain or register a low-privileged Control Panel (CP) user account on a vulnerable Statamic instance (versions 6.0.0–6.6.1).
  2. Authenticate and locate the preference endpoint: Log in to the Statamic CP and identify the color mode preference update endpoint at POST /cp/preferences/js.
  3. Inject malicious payload: Submit a crafted HTTP POST request to POST /cp/preferences/js with the color_mode preference value set to a JavaScript injection payload, e.g., ';window.XSS_POC_1337=1;//. This value is stored server-side without sanitization.
  4. Wait for administrator impersonation: The stored payload remains dormant until a higher-privileged administrator uses Statamic's built-in user impersonation feature to impersonate the attacker's account.
  5. Payload executes in admin context: When the administrator impersonates the attacker, the Control Panel loads the attacker's preferences and renders the malicious value into inline JavaScript without encoding, causing the injected code to execute in the administrator's browser session.
  6. Achieve objective: The attacker's JavaScript can steal session cookies, forge administrative actions, exfiltrate sensitive data, or perform further privilege escalation within the CMS (Shirshaw64p PoC, Statamic Advisory).

Indicators of compromise

  • Network: Unusual or repeated POST requests to /cp/preferences/js containing JavaScript syntax characters (e.g., single quotes, semicolons, window., document.cookie) in preference value fields.
  • Logs: Web server or application logs showing POST requests to /cp/preferences/js with anomalous or non-standard color_mode values; administrator impersonation events in Statamic audit logs shortly followed by unexpected outbound requests from the admin browser.
  • File System: No direct file system artifacts expected, as the payload is stored in the database/preferences store; review stored user preference records for unexpected JavaScript content in the color_mode field.
  • Process/Behavior: Unexpected JavaScript execution errors or network requests originating from the administrator's browser session during or after impersonation events; admin accounts performing actions inconsistent with normal behavior following impersonation (Shirshaw64p PoC).

Mitigation and workarounds

Upgrade Statamic CMS to version 6.6.2 or later, which addresses the vulnerability by implementing strict allowlist validation of preference values, safe JSON encoding for output, and avoiding raw Blade output ({!! !!}) for user-controlled data. As a workaround prior to patching, restrict Control Panel access to trusted users only and disable or limit use of the administrator impersonation feature. Monitoring preference fields for unexpected JavaScript content can provide additional detection coverage (Statamic Advisory, GitHub Advisory).

Community reactions

The vulnerability was responsibly disclosed by researcher Shirsendu Mondal (Shirshaw64p) of UNC Pembroke, and the Statamic security team acknowledged and patched the issue promptly in version 6.6.2. The advisory was published by Statamic maintainer jasonvarga on March 12, 2026, following coordinated disclosure practices. Coverage appeared on several CVE tracking and threat intelligence platforms shortly after disclosure, with no significant controversy or widespread community discussion noted (Statamic Advisory, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management