PT-2026-22406 · Statmatic · Statmatic

Mistz1

·

Published

2026-02-27

·

Updated

2026-03-10

·

CVE-2026-27939

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Statmatic versions 6.0.0 through 6.3.9
Description Statmatic is a Laravel and Git powered content management system (CMS). Authenticated Control Panel users may, under certain conditions, obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and potentially lead to privilege escalation, depending on the user’s existing permissions.
Recommendations Statmatic versions 6.0.0 through 6.3.9 should be updated to version 6.4.0.

Exploit

Fix

LPE

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-27939
GHSA-RW9X-PXQX-Q789

Affected Products

Statmatic