CVE-2026-64662 MEDIUM

CVE-2026-64662: Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

Vendor Statamic
Product cms
Weakness CWE-639 · IDOR
Published August 6, 2026
Last update August 6, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view content from entries they did not have permission to view, including entry content and custom field values, from any collection and including unpublished entries, through the navigation endpoint, though no data could be modified. This issue is fixed in versions 5.74.1 and 6.24.0.

Key dates

02Disclosure timeline

August 6, 2026 CVE published

Related vulnerabilities

04Related CVE