← Vulnerability feed

Vulnerability record · CVE-2026-33886 · published 27 March 2026

CVE-2026-33886: Statamic information exposure vulnerability

Statamic · Statamic

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.

6.5 CVSS 3.1 Medium EPSS 0.38% · top 70.7% CWE-200 · Information exposure
6.5CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33886 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47129Statamic unrestricted file upload vulnerabilityStatmic is a core Laravel content management system Composer package. Prior to versions 3.4.13 and 4.33.0, on front-end forms with an asset upload fi…EPSS 1.1%9.8CVE-2021-45364Statamic vulnerabilityA Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an err…EPSS 1.7%8.8CVE-2026-27939Statamic improper authentication vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control P…EPSS 0.46%8.8CVE-2026-27593Statamic weak password recovery vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability…EPSS 0.55%8.8CVE-2023-48217Statamic code injection vulnerabilityStatamic is a flat-first, Laravel + Git powered CMS designed for building websites. In affected versions certain additional PHP files crafted to look…EPSS 1.1%8.8CVE-2017-11422Statamic incorrect permission assignment vulnerabilityStatamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods…EPSS 0.87%8.7CVE-2026-33172Statamic cross-site scripting vulnerabilityStatamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS vulnerability in SVG asset r…EPSS 0.36%8.7CVE-2026-25759Statamic cross-site scripting vulnerabilityStatmatic is a Laravel and Git powered content management system (CMS). From 6.0.0 to before 6.2.3, a stored XSS vulnerability in content titles allo…EPSS 0.44%

Source: NIST National Vulnerability Database (record CVE-2026-33886), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.