Junglewise Threat Intelligence

CVE-2026-49287: Statamic CMS unsafe reflection in collection sorting

CVE-2026-49287 · Severity: high · CVSS 7.4 · Published 2026-06-19

Technologies: Statamic. Vendors: Statamic.

Executive brief

Statamic CMS, a content management system, contains a vulnerability that could allow an attacker to delete website content and assets. This occurs when a website's design allows visitors to control how lists of items are sorted. If exploited, this could lead to significant data loss and disruption of website operations.

Technical details

Statamic CMS is vulnerable to unsafe reflection (CWE-470) due to an incomplete fix for a previous vulnerability. The issue resides in how the CMS handles in-memory collection sorting when sort parameters are passed directly from request input to a template tag. An attacker can manipulate these sort parameters to invoke unintended methods, potentially leading to the deletion of content and assets. This vulnerability is only exploitable if a front-end template is explicitly configured to use visitor-controlled values for sorting. Patches are available in versions 5.73.23 and 6.20.0.

Affected products

  • Statamic Statamic CMS < 5.73.23, >= 6.0.0, < 6.20.0

Timeline

  • 2026-05-25: disclosed
  • 2026-06-19: advisory: NVD publication date
  • 2026-06-26: advisory: GitHub Advisory published

References

Related threats