PT-2026-28551 · Statamic · Statamic

Published

2026-03-26

·

Updated

2026-03-28

·

CVE-2026-33884

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Statamic versions prior to 5.73.16 Statamic versions prior to 6.7.2
Description An authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This issue affects the content management system (CMS) and potentially impacts users with access to the Control Panel and live preview functionality.
Recommendations Update to Statamic version 5.73.16 or later. Update to Statamic version 6.7.2 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33884
GHSA-8VWX-CCF6-5WG2

Affected Products

Statamic