Vulnerability record · CVE-2026-25633 · published 11 February 2026
CVE-2026-25633: Statamic missing authorization vulnerability
Statamic · Statamic
Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.
Description
Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/statamic/cms/commit/5a6f47246edf3a0c453727ffecbfa14333a6bc8a | PatchProduct |
| https://github.com/statamic/cms/releases/tag/v5.73.6 | Release Notes |
| https://github.com/statamic/cms/releases/tag/v6.2.5 | Release Notes |
| https://github.com/statamic/cms/security/advisories/GHSA-gwmx-9gcj-332h | Vendor Advisory |
Track CVE-2026-25633 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-25633), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.