
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33886 is an information disclosure vulnerability in Statamic CMS, a Laravel and Git-powered content management system, where authenticated control panel users with access to Antlers-enabled fields can expose sensitive application configuration values by injecting config variables into their content. The vulnerability affects Statamic versions 5.73.12 through 5.73.15 and 6.5.0 through 6.7.1. It was published on March 24, 2026, and patched versions were released the same day. It carries a CVSS v3.1 base score of 6.5 (Medium) (Github Advisory, Statamic Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Statamic's Antlers templating engine, when enabled on content fields in the control panel, does not sufficiently restrict access to Laravel application configuration variables. An authenticated user with low privileges can insert Antlers template syntax referencing config() variables directly into content fields, causing the template engine to evaluate and render sensitive configuration values (such as database credentials, API keys, or application secrets) when the content is processed or previewed. Exploitation requires only a valid control panel account with write access to at least one Antlers-enabled field — no additional privileges or user interaction are needed (Github Advisory, Statamic Advisory).
Successful exploitation results in a high confidentiality impact, with no effect on integrity or availability. An attacker with a low-privileged control panel account can exfiltrate sensitive Laravel application configuration values — potentially including database connection strings, API keys, mail server credentials, and other secrets stored in the application's configuration files or environment variables. This information could be leveraged for lateral movement, further system compromise, or credential theft (Github Advisory, Statamic Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.031% (0.000310), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access to the Statamic control panel with permissions to edit Antlers-enabled fields, which limits the attacker pool but does not eliminate risk in multi-tenant or shared CMS environments (Github Advisory).
{{ config:database.connections.mysql.password }} or {{ config:app.key }}.config: tag syntax (e.g., {{ config: patterns) submitted by non-administrative users; unusual access to content preview or rendering endpoints shortly after content edits.{{ config:app.key }} or {{ config:database.*}}.Statamic has released patched versions 5.73.16 and 6.7.2 that address this vulnerability. Users running versions 5.73.12–5.73.15 or 6.5.0–6.7.1 should upgrade immediately to the respective patched release. As a temporary workaround where upgrading is not immediately possible, administrators should audit and restrict control panel user permissions to remove access to Antlers-enabled fields for untrusted users, or disable Antlers parsing on sensitive content fields (Github Advisory, Statamic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."