CVE-2026-25633Disclosure(statamic / statamic)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • statamic

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
statamic

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 102-1102-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25633: Statamic CMS: The Peek-a-Boo Protocol (CVE-2026-25633) A granular access control failure in Statamic CMS allows authenticated Control Panel users to bypass container-specific permissions. By directly accessing asset controllers for PDF... https://cvereports.com/reports/CVE-2026-25633

    Post summary

    The post announces CVE-2026-25633, a granular access control flaw in Statamic CMS allowing authenticated users to bypass container permissions, but it provides no exploit code, patch info, or evidence of active exploitation.

    0000030
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25633 Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to downl… https://www.cve.org/CVERecord?id=CVE-2026-25633

    Post summary

    The post announces CVE‑2026‑25633, noting that unauthenticated users can download assets from Statamic CMS before versions 5.73.6 and 6.2.5, but provides no PoC, exploit, or patch details.

    00000154
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstatamicstatamic---

Explore more