CVE-2026-33882: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33882 is an information disclosure vulnerability in Statamic CMS where the markdown preview endpoint can be manipulated to return augmented data from arbitrary fieldtypes, exposing sensitive user information. Discovered and disclosed on March 24, 2026, it affects statamic/cms versions prior to 5.73.16 and versions 6.0.0 through 6.7.2 (exclusive). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), requiring only low privileges and no user interaction to exploit (GitHub Advisory, Statamic Advisory).

Technical details

The root cause is improper input validation (CWE-20) in Statamic's markdown preview endpoint, which fails to restrict the fieldtypes it will process when rendering preview data. An attacker can craft a request that instructs the endpoint to augment its response using the users fieldtype — or potentially other arbitrary fieldtypes — causing the application to return data it should not expose (CWE-200). Exploitation requires network access and a valid authenticated session with control panel access, but no elevated administrative privileges are needed. No public proof-of-concept code has been identified at this time (GitHub Advisory, Statamic Advisory).

Impact

Successful exploitation allows an authenticated control panel user to retrieve sensitive data belonging to other users of the Statamic application, including email addresses, encrypted passkey data, and encrypted two-factor authentication codes. While the encrypted credentials are not directly usable without further cryptographic attacks, their exposure increases the risk of offline cracking attempts and targeted phishing. There is no integrity or availability impact; the vulnerability is limited to confidentiality loss (GitHub Advisory).

Exploitability

No public exploit code or in-the-wild exploitation has been reported for CVE-2026-33882. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.106% (28th percentile), indicating a low near-term probability of exploitation. Exploitation requires authenticated access to the Statamic control panel, which limits the attacker pool to insiders or users who have already compromised a low-privileged account (GitHub Advisory).

Exploitation steps

  1. Obtain Control Panel Access: Authenticate to the Statamic CMS control panel with any low-privileged user account that has access to the markdown preview feature.
  2. Identify the Markdown Preview Endpoint: Locate the API endpoint used by the control panel for rendering markdown previews (typically an internal REST endpoint called during content editing).
  3. Craft a Malicious Request: Manipulate the request parameters sent to the markdown preview endpoint to specify the users fieldtype (or another sensitive fieldtype) as the augmentation source, rather than the expected markdown content fieldtype.
  4. Retrieve Sensitive Data: Submit the crafted request and parse the augmented response, which will include sensitive user data such as email addresses, encrypted passkey data, and encrypted two-factor authentication codes for other users.
  5. Leverage Exfiltrated Data: Use the retrieved email addresses for targeted phishing, or attempt offline decryption of the passkey and 2FA data to escalate access (GitHub Advisory, Statamic Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to the Statamic markdown preview endpoint with unexpected fieldtype parameters (e.g., users fieldtype references in preview request bodies); requests originating from authenticated sessions that do not correspond to normal editorial workflows.
  • Logs: Application or web server access logs showing authenticated POST/GET requests to the markdown preview endpoint with anomalous payload structures or fieldtype parameters not consistent with normal content editing activity.
  • Application Behavior: Responses from the markdown preview endpoint containing user PII fields (email addresses, passkey data, 2FA codes) that would not normally appear in preview output.

Mitigation and workarounds

Statamic has released patched versions 5.73.16 and 6.7.2 that fix this vulnerability. Users running any version of statamic/cms below 5.73.16 (v5 branch) or between 6.0.0 and 6.7.2 (v6 branch) should upgrade immediately. No configuration-based workaround has been published; upgrading to a patched version is the only recommended remediation. Organizations should also audit control panel user accounts and restrict access to the minimum necessary set of users as a defense-in-depth measure (GitHub Advisory, Statamic Advisory).

Community reactions

The advisory was published by Statamic maintainer jasonvarga on March 24, 2026, and credited reporter joshuaalwin for discovering the issue. The vulnerability was reviewed and added to the GitHub Advisory Database on March 26, 2026, and published by the National Vulnerability Database on March 27, 2026. No significant broader media coverage or notable community commentary beyond the official advisory has been identified (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management