CVE 5.4 MEDIUM

Statamic allows unauthorized content access through missing authorization in its revision controllers_CVE-2026-33887

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the authorization checks that the main entry controllers enforce, exposing entry field values and blueprint data. Users could also create entry revisions without edit permission, though this only snapshots the existing content state and does not affect published content. This has been fixed in 5.73.16 and 6.7.2.

Basic Information

ID CVE-2026-33887
Source GitHub_M
Published Mar 27, 2026 at 20:41
Modified Mar 30, 2026 at 18:54

Affected Product

Vendor statamic
Product cms
Version < 5.73.16
Affected Versions statamic cms < 5.73.16
statamic cms >= 6.0.0-alpha.1, < 6.7.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.