CVE-2026-33177: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33177 is a missing authorization vulnerability in Statamic CMS that allows low-privileged Control Panel users to create taxonomy terms by bypassing standard authorization checks. The flaw affects all Statamic versions prior to 5.73.14 (v5 branch) and versions 6.0.0-alpha.1 through 6.7.0 (v6 branch). It was disclosed on March 17, 2026, by researcher everythingBlackkk and published to the GitHub Advisory Database on March 18, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Statamic Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization). Statamic's field action processing endpoint does not enforce the same authorization checks as the standard taxonomy term creation endpoint, allowing an attacker to submit requests with attacker-controlled field definitions to create taxonomy terms without the required permissions. Exploitation requires only low-level authenticated access to the Control Panel — no special privileges, user interaction, or complex conditions are needed beyond a valid low-privileged account (GitHub Advisory, Statamic Advisory).

Impact

Successful exploitation allows unauthorized modification of CMS content by creating taxonomy terms that the attacker would not normally be permitted to create. The impact is limited to integrity — there is no confidentiality or availability impact, and the scope is unchanged. While the vulnerability does not enable remote code execution or data exfiltration, it could allow low-privileged users to pollute or manipulate the taxonomy structure of a Statamic-powered site (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.009% (0.000090), placing it in the 3rd percentile for exploitation likelihood within 30 days (GitHub Advisory, Feedly).

Exploitation steps

  1. Authenticate: Log in to the Statamic Control Panel with any low-privileged user account that would not normally have permission to create taxonomy terms.
  2. Identify the field action endpoint: Locate the field action processing endpoint within the Statamic application (distinct from the standard taxonomy term creation endpoint).
  3. Craft a malicious request: Construct an HTTP request targeting the field action processing endpoint, including attacker-controlled field definitions that reference or trigger taxonomy term creation.
  4. Submit the request: Send the crafted request to the endpoint; because authorization checks are absent on this endpoint, the server processes the request and creates the taxonomy term without validating the user's permissions.
  5. Verify outcome: Confirm that the new taxonomy term has been created in the CMS, demonstrating the authorization bypass (GitHub Advisory, Statamic Advisory).

Indicators of compromise

  • Logs: Unexpected HTTP POST requests to the Statamic field action processing endpoint from low-privileged user accounts, particularly with field definition parameters not consistent with normal UI usage.
  • Application Data: Unexplained or unauthorized taxonomy terms appearing in the CMS that were not created by users with appropriate permissions.
  • Logs: Statamic application logs showing taxonomy term creation events attributed to low-privileged accounts outside of normal business hours or workflows.

Mitigation and workarounds

Statamic has released patched versions 5.73.14 (for the v5 branch) and 6.7.0 (for the v6 branch) that enforce proper authorization checks on the field action processing endpoint. Users should upgrade to one of these versions immediately. No configuration-based workarounds have been published; upgrading is the only recommended remediation (GitHub Advisory, Statamic Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management