CVE-2026-33884: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33884 is an incorrect authorization vulnerability in Statamic CMS that allows an authenticated Control Panel user with live preview access to use a live preview token to access restricted content that the token was not intended for. It affects Statamic versions prior to 5.73.16 and versions 6.0.0-alpha.1 through 6.7.2 (prior to 6.7.2). The vulnerability was published on March 24, 2026, by maintainer jasonvarga, and added to the GitHub Advisory Database on March 26, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Statamic Advisory).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization): the live preview token mechanism in Statamic's Control Panel does not correctly validate that a token is scoped to the specific content entry it was generated for. As a result, an authenticated user can reuse or redirect a valid live preview token to request and view restricted content entries that the token was not originally issued to access. Exploitation requires network access and low-level authenticated privileges (a Control Panel account with live preview permissions), but no user interaction or elevated scope is needed (GitHub Advisory, Statamic Advisory).

Impact

Successful exploitation results in unauthorized read access to restricted CMS content entries that the attacker's live preview token was not intended to expose. The impact is limited to confidentiality — there is no integrity or availability impact — and the scope is confined to the affected Statamic instance. This could expose draft content, unpublished entries, or access-controlled pages to authenticated users who should not have permission to view them (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (12th percentile), indicating a very low probability of exploitation in the near term. The vulnerability requires an authenticated Control Panel account with live preview access, which significantly limits the attacker pool. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Obtain authenticated access: Log in to the Statamic Control Panel with an account that has live preview permissions.
  2. Generate a live preview token: Navigate to a content entry accessible to the attacker's account and initiate a live preview session, capturing the preview token issued by the application (e.g., via browser developer tools or intercepting the HTTP request with a proxy like Burp Suite).
  3. Identify a restricted target entry: Determine the identifier (e.g., entry ID or slug) of a restricted content entry that the attacker's account should not have access to.
  4. Reuse the token for the restricted entry: Craft an HTTP request to the live preview endpoint, substituting the target restricted entry's identifier while supplying the previously obtained live preview token.
  5. Access restricted content: The server incorrectly accepts the token without validating it is scoped to the original entry, returning the restricted content in the response (GitHub Advisory, Statamic Advisory).

Indicators of compromise

  • Logs: Statamic/Laravel application logs showing live preview token requests referencing entry IDs or slugs that differ from the entry the token was originally generated for; repeated preview requests from the same authenticated user targeting multiple different restricted entries in a short timeframe.
  • Network: HTTP requests to the live preview endpoint (typically /cp/preview or similar Statamic preview routes) with token parameters being reused across different content entry identifiers.
  • Application Behavior: Access log entries showing a Control Panel user successfully retrieving content entries they do not have explicit read permissions for via the preview mechanism.

Mitigation and workarounds

Statamic has released patched versions 5.73.16 and 6.7.2 that fix this vulnerability by correctly scoping live preview tokens to their intended content entries. Users running any version of Statamic prior to 5.73.16 (v5 branch) or between 6.0.0-alpha.1 and 6.7.2 (v6 branch) should upgrade immediately. No configuration-based workaround is documented; upgrading to a patched version is the recommended and only confirmed remediation (GitHub Advisory, Statamic Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management