CVE-2026-64662

medium

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.

References

https://github.com/statamic/cms/security/advisories/GHSA-qh8c-7588-qfrv

https://github.com/statamic/cms/releases/tag/v6.24.0

https://github.com/statamic/cms/releases/tag/v5.74.1

https://github.com/statamic/cms/pull/14906

https://github.com/statamic/cms/commit/6557f1d8a0d61c0e7ad9c9a8f42cb3288607495d

Details

Source: Mitre, NVD

Published: 2026-08-06

Updated: 2026-08-06

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00305