
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33884 is an incorrect authorization vulnerability in Statamic CMS that allows an authenticated Control Panel user with live preview access to use a live preview token to access restricted content that the token was not intended for. It affects Statamic versions prior to 5.73.16 and versions 6.0.0-alpha.1 through 6.7.2 (prior to 6.7.2). The vulnerability was published on March 24, 2026, by maintainer jasonvarga, and added to the GitHub Advisory Database on March 26, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Statamic Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization): the live preview token mechanism in Statamic's Control Panel does not correctly validate that a token is scoped to the specific content entry it was generated for. As a result, an authenticated user can reuse or redirect a valid live preview token to request and view restricted content entries that the token was not originally issued to access. Exploitation requires network access and low-level authenticated privileges (a Control Panel account with live preview permissions), but no user interaction or elevated scope is needed (GitHub Advisory, Statamic Advisory).
Successful exploitation results in unauthorized read access to restricted CMS content entries that the attacker's live preview token was not intended to expose. The impact is limited to confidentiality — there is no integrity or availability impact — and the scope is confined to the affected Statamic instance. This could expose draft content, unpublished entries, or access-controlled pages to authenticated users who should not have permission to view them (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (12th percentile), indicating a very low probability of exploitation in the near term. The vulnerability requires an authenticated Control Panel account with live preview access, which significantly limits the attacker pool. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
/cp/preview or similar Statamic preview routes) with token parameters being reused across different content entry identifiers.Statamic has released patched versions 5.73.16 and 6.7.2 that fix this vulnerability by correctly scoping live preview tokens to their intended content entries. Users running any version of Statamic prior to 5.73.16 (v5 branch) or between 6.0.0-alpha.1 and 6.7.2 (v6 branch) should upgrade immediately. No configuration-based workaround is documented; upgrading to a patched version is the recommended and only confirmed remediation (GitHub Advisory, Statamic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."