CVE-2026-54244Low· 3.5▾ SunlitStatamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
The Live Preview endpoint for existing entries and terms only checked view authorization, but it accepts and renders caller-supplied field values. A Control Panel user with view but not edit permission could therefore submit content they were not authorized to author and generate a shareable Live Preview URL rendering it.
This has been fixed in 5.74.0 and 6.20.3.
statamic/cms < 5.74.0statamic/cms >= 6.0.0, < 6.20.3Upgrade to a patched release:
statamic/cms 5.74.0statamic/cms 6.20.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49288Medium· 4.3Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
CVE-2026-64664Medium· 4.3Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-64665High· 8.1Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-64663Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-64662Medium· 6.5Statamic is a Laravel and Git powered content management system (CMS)
CVE-2026-71434Medium· 5.3Statamic is a Laravel and Git powered content management system (CMS)