CVE-2026-49288
PHP vulnerability analysis and mitigation

Overview

CVE-2026-49288 is an authorization bypass vulnerability in Statamic CMS, a Laravel and Git-powered content management system, that allows authenticated Control Panel users to view metadata and content for resources they are not permitted to access. The flaw affects all versions prior to 5.73.23 and versions 6.0.0 through 6.20.0 (exclusive). It was originally published by the maintainer on May 25, 2026, added to the NVD on June 19, 2026, and formally reviewed in the GitHub Advisory Database on June 26, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Statamic Advisory).

Technical details

The root cause is missing or incorrect authorization checks on Control Panel fieldtype endpoints (CWE-862: Missing Authorization; CWE-863: Incorrect Authorization; CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). When an authenticated Control Panel user interacts with these endpoints, the application fails to enforce the configured permission model, allowing the user to retrieve metadata and content — such as titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups — for resources outside their authorized scope. Exploitation requires only a valid, low-privileged Control Panel account and a network-accessible Statamic instance; no special configuration or user interaction is needed. No public proof-of-concept code has been identified (GitHub Advisory, Statamic Advisory).

Impact

Successful exploitation results in unauthorized disclosure of CMS content and metadata, including entry titles, custom field values, full entry content, asset metadata, and the existence of users, roles, and groups. The impact is limited to confidentiality — no data modification or deletion is possible, and availability is unaffected. The scope of exposure depends on the sensitivity of the restricted resources configured within the Statamic instance, and could facilitate reconnaissance for further attacks if user or role information is exposed (GitHub Advisory, Statamic Advisory).

Exploitation steps

  1. Obtain Control Panel access: Acquire a valid, low-privileged Statamic Control Panel account (e.g., a contributor or editor role with limited resource permissions).
  2. Identify target endpoints: Locate the Control Panel fieldtype API endpoints that handle resource lookups (e.g., relationship or asset fieldtype endpoints used for entry/asset selection).
  3. Craft unauthorized requests: Send authenticated HTTP requests to these fieldtype endpoints referencing resource identifiers (entry IDs, asset paths, user handles) that the account is not authorized to view.
  4. Retrieve restricted metadata: Parse the API responses to extract titles, custom field values, entry content, asset metadata, or user/role/group existence information that would normally be restricted by the CMS permission model.
  5. Enumerate further: Repeat with different resource identifiers to map out the full scope of restricted content accessible through the bypass (GitHub Advisory, Statamic Advisory).

Indicators of compromise

  • Logs: Statamic/Laravel access logs showing authenticated Control Panel users making repeated API requests to fieldtype endpoints (e.g., /cp/fieldtypes/ or similar relationship/asset lookup routes) for resources outside their normal workflow.
  • Logs: Unusual patterns of resource ID enumeration in HTTP request logs — sequential or bulk requests to resource lookup endpoints from a single authenticated session.
  • Network: Elevated volume of authenticated API calls to Control Panel endpoints from accounts with limited roles, particularly outside normal business hours.
  • Application Logs: Laravel application logs recording access to entries, assets, users, roles, or groups by users whose permission set should not include those resources.

Mitigation and workarounds

Statamic has released patched versions 5.73.23 and 6.20.0 that address this vulnerability. All users running versions below 5.73.23 or between 6.0.0 and 6.20.0 should upgrade immediately. No configuration-based workaround is documented; upgrading is the only recommended remediation. After patching, administrators should review Control Panel access logs for suspicious resource access prior to the patch date and audit sensitive resources to assess whether unauthorized viewing occurred (GitHub Advisory, Statamic Advisory).

Community reactions

The advisory was published by Statamic maintainer jasonvarga and credited reporters offset, Eszh, and geo-chen for responsible disclosure. The vulnerability received routine coverage from CVE aggregation services (Vulners, VulDB, cvefeed.io) and was picked up by automated CVE notification accounts on social media shortly after NVD publication. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries (Statamic Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-48030CRITICAL9.9
  • PHP logoPHP
  • pheditor/pheditor
NoYesJul 27, 2026
CVE-2026-55579CRITICAL9.8
  • PHP logoPHP
  • pheditor/pheditor
NoYesJul 27, 2026
CVE-2026-55578HIGH8.8
  • PHP logoPHP
  • pheditor/pheditor
NoYesJul 27, 2026
CVE-2026-54540HIGH8.8
  • PHP logoPHP
  • pheditor/pheditor
NoYesJul 27, 2026
GHSA-cmwh-g2h8-c222HIGH8.1
  • PHP logoPHP
  • poweradmin/poweradmin
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management