PT-2026-22424 · Statamic · Statamic
Jason Varga
·
Published
2026-02-27
·
Updated
2026-03-05
·
CVE-2026-28425
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Statamic versions prior to 5.73.11 and prior to 6.4.0
Description
Statamic is a Laravel and Git powered content management system (CMS). An authenticated control panel user with access to Antlers-enabled inputs may be able to achieve remote code execution in the application context. This could lead to a full compromise of the application, including access to sensitive configuration, modification or exfiltration of data, and potential impact on availability. Exploitation is possible where Antlers runs on user-controlled content, such as content fields with Antlers explicitly enabled, built-in configuration supporting Antlers like Forms email notification settings, or third-party addons adding Antlers-enabled fields. The attacker must have the relevant control panel permissions.
Recommendations
Versions prior to 5.73.11 should be updated to version 5.73.11 or later.
Versions prior to 6.4.0 should be updated to version 6.4.0 or later.
If using addons that depend on Statamic, ensure a patched Statamic version is running after updating the addons.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Statamic