
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-49288 is an authorization bypass vulnerability in Statamic CMS, a Laravel and Git-powered content management system, that allows authenticated Control Panel users to view metadata and content for resources they are not permitted to access. The flaw affects all versions prior to 5.73.23 and versions 6.0.0 through 6.20.0 (exclusive). It was originally published by the maintainer on May 25, 2026, added to the NVD on June 19, 2026, and formally reviewed in the GitHub Advisory Database on June 26, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Statamic Advisory).
The root cause is missing or incorrect authorization checks on Control Panel fieldtype endpoints (CWE-862: Missing Authorization; CWE-863: Incorrect Authorization; CWE-200: Exposure of Sensitive Information to an Unauthorized Actor). When an authenticated Control Panel user interacts with these endpoints, the application fails to enforce the configured permission model, allowing the user to retrieve metadata and content — such as titles, custom field values, entry content, asset metadata, and the existence of users, roles, and groups — for resources outside their authorized scope. Exploitation requires only a valid, low-privileged Control Panel account and a network-accessible Statamic instance; no special configuration or user interaction is needed. No public proof-of-concept code has been identified (GitHub Advisory, Statamic Advisory).
Successful exploitation results in unauthorized disclosure of CMS content and metadata, including entry titles, custom field values, full entry content, asset metadata, and the existence of users, roles, and groups. The impact is limited to confidentiality — no data modification or deletion is possible, and availability is unaffected. The scope of exposure depends on the sensitivity of the restricted resources configured within the Statamic instance, and could facilitate reconnaissance for further attacks if user or role information is exposed (GitHub Advisory, Statamic Advisory).
/cp/fieldtypes/ or similar relationship/asset lookup routes) for resources outside their normal workflow.Statamic has released patched versions 5.73.23 and 6.20.0 that address this vulnerability. All users running versions below 5.73.23 or between 6.0.0 and 6.20.0 should upgrade immediately. No configuration-based workaround is documented; upgrading is the only recommended remediation. After patching, administrators should review Control Panel access logs for suspicious resource access prior to the patch date and audit sensitive resources to assess whether unauthorized viewing occurred (GitHub Advisory, Statamic Advisory).
The advisory was published by Statamic maintainer jasonvarga and credited reporters offset, Eszh, and geo-chen for responsible disclosure. The vulnerability received routine coverage from CVE aggregation services (Vulners, VulDB, cvefeed.io) and was picked up by automated CVE notification accounts on social media shortly after NVD publication. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries (Statamic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."