
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33177 is a missing authorization vulnerability in Statamic CMS that allows low-privileged Control Panel users to create taxonomy terms by bypassing standard authorization checks. The flaw affects all Statamic versions prior to 5.73.14 (v5 branch) and versions 6.0.0-alpha.1 through 6.7.0 (v6 branch). It was disclosed on March 17, 2026, by researcher everythingBlackkk and published to the GitHub Advisory Database on March 18, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Statamic Advisory).
The root cause is classified as CWE-862 (Missing Authorization). Statamic's field action processing endpoint does not enforce the same authorization checks as the standard taxonomy term creation endpoint, allowing an attacker to submit requests with attacker-controlled field definitions to create taxonomy terms without the required permissions. Exploitation requires only low-level authenticated access to the Control Panel — no special privileges, user interaction, or complex conditions are needed beyond a valid low-privileged account (GitHub Advisory, Statamic Advisory).
Successful exploitation allows unauthorized modification of CMS content by creating taxonomy terms that the attacker would not normally be permitted to create. The impact is limited to integrity — there is no confidentiality or availability impact, and the scope is unchanged. While the vulnerability does not enable remote code execution or data exfiltration, it could allow low-privileged users to pollute or manipulate the taxonomy structure of a Statamic-powered site (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.009% (0.000090), placing it in the 3rd percentile for exploitation likelihood within 30 days (GitHub Advisory, Feedly).
Statamic has released patched versions 5.73.14 (for the v5 branch) and 6.7.0 (for the v6 branch) that enforce proper authorization checks on the field action processing endpoint. Users should upgrade to one of these versions immediately. No configuration-based workarounds have been published; upgrading is the only recommended remediation (GitHub Advisory, Statamic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."