
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33882 is an information disclosure vulnerability in Statamic CMS where the markdown preview endpoint can be manipulated to return augmented data from arbitrary fieldtypes, exposing sensitive user information. Discovered and disclosed on March 24, 2026, it affects statamic/cms versions prior to 5.73.16 and versions 6.0.0 through 6.7.2 (exclusive). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), requiring only low privileges and no user interaction to exploit (GitHub Advisory, Statamic Advisory).
The root cause is improper input validation (CWE-20) in Statamic's markdown preview endpoint, which fails to restrict the fieldtypes it will process when rendering preview data. An attacker can craft a request that instructs the endpoint to augment its response using the users fieldtype — or potentially other arbitrary fieldtypes — causing the application to return data it should not expose (CWE-200). Exploitation requires network access and a valid authenticated session with control panel access, but no elevated administrative privileges are needed. No public proof-of-concept code has been identified at this time (GitHub Advisory, Statamic Advisory).
Successful exploitation allows an authenticated control panel user to retrieve sensitive data belonging to other users of the Statamic application, including email addresses, encrypted passkey data, and encrypted two-factor authentication codes. While the encrypted credentials are not directly usable without further cryptographic attacks, their exposure increases the risk of offline cracking attempts and targeted phishing. There is no integrity or availability impact; the vulnerability is limited to confidentiality loss (GitHub Advisory).
No public exploit code or in-the-wild exploitation has been reported for CVE-2026-33882. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.106% (28th percentile), indicating a low near-term probability of exploitation. Exploitation requires authenticated access to the Statamic control panel, which limits the attacker pool to insiders or users who have already compromised a low-privileged account (GitHub Advisory).
users fieldtype (or another sensitive fieldtype) as the augmentation source, rather than the expected markdown content fieldtype.users fieldtype references in preview request bodies); requests originating from authenticated sessions that do not correspond to normal editorial workflows.Statamic has released patched versions 5.73.16 and 6.7.2 that fix this vulnerability. Users running any version of statamic/cms below 5.73.16 (v5 branch) or between 6.0.0 and 6.7.2 (v6 branch) should upgrade immediately. No configuration-based workaround has been published; upgrading to a patched version is the only recommended remediation. Organizations should also audit control panel user accounts and restrict access to the minimum necessary set of users as a defense-in-depth measure (GitHub Advisory, Statamic Advisory).
The advisory was published by Statamic maintainer jasonvarga on March 24, 2026, and credited reporter joshuaalwin for discovering the issue. The vulnerability was reviewed and added to the GitHub Advisory Database on March 26, 2026, and published by the National Vulnerability Database on March 27, 2026. No significant broader media coverage or notable community commentary beyond the official advisory has been identified (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."