CVE-2026-33171: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33171 is a path traversal vulnerability in Statamic CMS that allows authenticated Control Panel users to read arbitrary .json, .yaml, and .csv files from the server by manipulating the filename configuration parameter in the file dictionary fieldtype's endpoint. It affects all Statamic versions prior to 5.73.14 (v5 branch) and versions 6.0.0 through 6.6.x (prior to 6.7.0). The vulnerability was published on March 17, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Github Advisory, github.com).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal): the file dictionary fieldtype's endpoint does not properly sanitize or restrict the filename configuration parameter supplied by the user, allowing path traversal sequences to escape the intended directory boundary. An authenticated attacker can craft a request to the fieldtype's endpoint with a manipulated filename value (e.g., containing ../ sequences) to reference files outside the permitted directory. Exploitation requires only low-privilege authenticated access to the Statamic Control Panel and no user interaction, making it straightforward for any valid CP user to abuse (Github Advisory, github.com).

Impact

Successful exploitation allows an authenticated Control Panel user to read arbitrary .json, .yaml, and .csv files from the server's filesystem, which may include application configuration files, environment files, API keys, database credentials, and other sensitive data stored in those formats. There is no impact on integrity or availability; the vulnerability is limited to confidentiality. However, disclosure of credentials or configuration secrets could enable further compromise, privilege escalation, or lateral movement within the environment (Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.022% (6th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to authenticated Control Panel users, which limits the attacker pool but does not eliminate insider or compromised-account risk.

Exploitation steps

  1. Gain Control Panel Access: Obtain valid Statamic Control Panel credentials — either through phishing, credential stuffing, or a compromised account with at least low-privilege CP access.
  2. Identify the File Dictionary Fieldtype Endpoint: Locate the API or internal endpoint used by the file dictionary fieldtype (typically an AJAX/REST endpoint called during CP field interactions).
  3. Craft a Malicious Request: Intercept or manually construct a request to the fieldtype's endpoint, modifying the filename configuration parameter to include path traversal sequences (e.g., ../../config/database.yaml or ../../.env.json).
  4. Read Arbitrary Files: Submit the crafted request; the server processes the manipulated filename without proper sanitization and returns the contents of the targeted .json, .yaml, or .csv file.
  5. Exfiltrate Sensitive Data: Review returned file contents for credentials, API keys, database connection strings, or other sensitive configuration data that can be leveraged for further access (Github Advisory, github.com).

Indicators of compromise

  • Network: Unusual HTTP requests to the Statamic file dictionary fieldtype endpoint containing path traversal patterns (e.g., ../, %2e%2e%2f, or encoded variants) in the filename parameter.
  • Logs: Web server or application logs showing requests to the fieldtype endpoint with abnormal filename values referencing files outside expected directories; repeated access attempts to configuration-related paths (e.g., config/, .env, database).
  • File System: No direct file system artifacts are expected from read-only exploitation, but access timestamps on sensitive .json, .yaml, or .csv files may be updated unexpectedly.
  • Application Logs: Statamic or Laravel application logs recording unusual file access or errors triggered by out-of-bounds path resolution attempts.

Mitigation and workarounds

Upgrade Statamic CMS to version 5.73.14 (for the v5 branch) or 6.7.0 (for the v6 branch), which contain the fix for this vulnerability (Github Advisory, github.com). As interim mitigations, restrict Control Panel access to trusted users and trusted network segments only, and monitor CP activity for suspicious file access patterns. No official configuration-only workaround has been published by the vendor.

Community reactions

A Medium article by researcher spbavarva (credited as the reporter) was published covering CVE-2026-33171, providing a write-up on the path traversal issue in Statamic CMS (Github Advisory). The vulnerability received routine coverage from vulnerability tracking services such as VulDB, cvefeed.io, and radar.offseq.com. Community reaction has been limited given the moderate severity and authentication requirement.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management