Junglewise Threat Intelligence

CVE-2026-49288: Statamic CMS incorrect authorization in Control Panel fieldtype endpoints

CVE-2026-49288 · Severity: medium · CVSS 4.3 · Published 2026-06-19

Technologies: Statamic. Vendors: Statamic.

Executive brief

Statamic CMS, a content management system used for building and managing websites, contains a vulnerability where authenticated users can access information they are not authorized to see. An attacker with access to the Control Panel could view sensitive metadata and content, including user lists, roles, and internal assets. While attackers cannot modify or delete data, this exposure could lead to the disclosure of private business information or internal site structures.

Technical details

A missing authorization vulnerability exists in Statamic CMS within the Control Panel fieldtype endpoints. An authenticated attacker with low privileges can bypass intended access controls to query metadata and content for restricted resources such as entries, assets, users, roles, and groups. This is classified as an Information Exposure (CWE-200) resulting from Missing Authorization (CWE-862). The exploit allows for the disclosure of titles, custom field values, and asset metadata, though it does not permit data modification. The issue is resolved in versions 5.73.23 and 6.20.0.

Affected products

  • Statamic Statamic CMS < 5.73.23, >= 6.0.0, < 6.20.0

Timeline

  • 2026-05-25: disclosed: Initial disclosure to vendor
  • 2026-06-19: advisory: NVD publication date
  • 2026-06-26: patched: GitHub Advisory published and fix confirmed

References

Related threats