PT-2026-7664 · Statamic · Statamic

Neosprings

·

Published

2026-02-11

·

Updated

2026-02-18

·

CVE-2026-25633

CVSS v3.1

4.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Statamic versions prior to 5.73.6 Statamic versions prior to 6.2.5
Description Statamic is a Laravel and Git powered CMS designed for building websites. Users without the necessary permissions to view assets are able to download them and view their metadata. Logged-out users and users without access to the control panel are not affected by this issue.
Recommendations Update to version 5.73.6 or later. Update to version 6.2.5 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25633
GHSA-GWMX-9GCJ-332H

Affected Products

Statamic