CVE-2026-33886: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33886 is an information disclosure vulnerability in Statamic CMS, a Laravel and Git-powered content management system, where authenticated control panel users with access to Antlers-enabled fields can expose sensitive application configuration values by injecting config variables into their content. The vulnerability affects Statamic versions 5.73.12 through 5.73.15 and 6.5.0 through 6.7.1. It was published on March 24, 2026, and patched versions were released the same day. It carries a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Statamic Advisory).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Statamic's Antlers templating engine, when enabled on content fields in the control panel, does not sufficiently restrict access to Laravel application configuration variables. An authenticated user with low privileges can insert Antlers template syntax referencing config() variables directly into content fields, causing the template engine to evaluate and render sensitive configuration values (such as database credentials, API keys, or application secrets) when the content is processed or previewed. Exploitation requires only a valid control panel account with write access to at least one Antlers-enabled field — no additional privileges or user interaction are needed (Github Advisory, Statamic Advisory).

Impact

Successful exploitation results in a high confidentiality impact, with no effect on integrity or availability. An attacker with a low-privileged control panel account can exfiltrate sensitive Laravel application configuration values — potentially including database connection strings, API keys, mail server credentials, and other secrets stored in the application's configuration files or environment variables. This information could be leveraged for lateral movement, further system compromise, or credential theft (Github Advisory, Statamic Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.031% (0.000310), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access to the Statamic control panel with permissions to edit Antlers-enabled fields, which limits the attacker pool but does not eliminate risk in multi-tenant or shared CMS environments (Github Advisory).

Exploitation steps

  1. Gain authenticated access: Obtain a Statamic control panel account with at least low-level privileges and access to one or more Antlers-enabled content fields (e.g., a rich text or textarea field configured to parse Antlers syntax).
  2. Identify Antlers-enabled fields: Navigate the control panel to locate content entry forms where Antlers templating is enabled, such as blog post bodies or page content fields.
  3. Inject config variable syntax: Insert an Antlers template expression referencing a sensitive configuration key into the field content, for example: {{ config:database.connections.mysql.password }} or {{ config:app.key }}.
  4. Trigger template rendering: Save the content entry and preview or publish it, causing the Antlers engine to evaluate the injected expression and render the configuration value in the output.
  5. Exfiltrate the value: Read the rendered output (via the frontend page, preview, or API response) to obtain the sensitive configuration data (Github Advisory, Statamic Advisory).

Indicators of compromise

  • Logs: Statamic or Laravel application logs showing content entries containing Antlers config: tag syntax (e.g., {{ config: patterns) submitted by non-administrative users; unusual access to content preview or rendering endpoints shortly after content edits.
  • File System: Content files (flat-file CMS entries) in the Statamic content directory containing Antlers config variable expressions such as {{ config:app.key }} or {{ config:database.*}}.
  • Application Behavior: Rendered frontend pages or API responses unexpectedly containing application secret values, database credentials, or environment-specific configuration strings.

Mitigation and workarounds

Statamic has released patched versions 5.73.16 and 6.7.2 that address this vulnerability. Users running versions 5.73.12–5.73.15 or 6.5.0–6.7.1 should upgrade immediately to the respective patched release. As a temporary workaround where upgrading is not immediately possible, administrators should audit and restrict control panel user permissions to remove access to Antlers-enabled fields for untrusted users, or disable Antlers parsing on sensitive content fields (Github Advisory, Statamic Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management