CVE-2026-33885: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33885 is an open redirect vulnerability in Statamic CMS, a Laravel and Git-powered content management system, caused by a URL parsing differential that allows bypass of external URL detection on unauthenticated endpoints. Attackers can exploit this to redirect users to arbitrary external URLs following actions such as form submissions and authentication flows. The vulnerability affects all Statamic versions prior to 5.73.16 and versions 6.0.0 through 6.7.1. It was published on March 24, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Statamic Advisory).

Technical details

The root cause is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect). The vulnerability stems from a differential in how the application parses URLs during redirect validation — the external URL detection logic on unauthenticated endpoints can be bypassed by crafting URLs that are interpreted differently by the validation layer versus the redirect handler. No authentication is required to trigger the flaw; however, user interaction is needed (e.g., a victim must click a crafted link or submit a form). The affected endpoints include authentication flows and form submission handlers (GitHub Advisory, Statamic Advisory).

Impact

Successful exploitation allows an attacker to redirect authenticated or unauthenticated users from a trusted Statamic site to an arbitrary external URL, enabling phishing attacks, credential harvesting, or malware delivery. The scope change in the CVSS score reflects that the impact crosses security boundaries — users trusting the legitimate Statamic domain may be silently sent to attacker-controlled infrastructure. Confidentiality and integrity are both assessed as low impact, and availability is unaffected (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.037–0.052%, placing it in the 17th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no privileges but does require user interaction, limiting its severity relative to fully unauthenticated, no-interaction vulnerabilities (GitHub Advisory, Statamic Advisory).

Exploitation steps

  1. Identify target: Locate a publicly accessible Statamic CMS instance running a version prior to 5.73.16 or between 6.0.0 and 6.7.1.
  2. Identify vulnerable endpoints: Locate unauthenticated endpoints that perform redirects after user actions, such as form submission handlers or post-authentication redirect parameters.
  3. Craft bypass URL: Construct a URL that passes Statamic's external URL detection check but resolves to an external domain — for example, using URL parsing differentials such as //evil.com, https:evil.com, or Unicode/encoded variants that fool the validator but are followed by the redirect handler.
  4. Deliver to victim: Embed the crafted URL in a phishing email, social media post, or other medium, directing the victim to click a link pointing to the legitimate Statamic site with the malicious redirect parameter.
  5. Victim redirected: When the victim interacts with the endpoint (e.g., submits a form or completes an authentication flow), they are transparently redirected to the attacker-controlled external URL (GitHub Advisory, Statamic Advisory).

Indicators of compromise

  • Network: Outbound HTTP 302/301 redirect responses from the Statamic server pointing to unexpected external domains, particularly following POST requests to form or authentication endpoints.
  • Logs: Web server access logs showing requests to form submission or login endpoints with redirect, return, or similar parameters containing external URLs or obfuscated variants (e.g., //, %2F%2F, Unicode-encoded hostnames).
  • Logs: Application logs recording redirect targets that do not match the configured site domain.
  • Network: Unusual referrer traffic arriving at external/attacker-controlled domains originating from the Statamic site's domain.

Mitigation and workarounds

Statamic has released patched versions 5.73.16 and 6.7.2 that correct the URL parsing differential used to bypass external redirect validation. Users should upgrade to one of these versions immediately. No official configuration-based workaround has been published; upgrading is the recommended and only confirmed remediation (GitHub Advisory, Statamic Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management