CVE-2026-27939Disclosure(statamic / statamic)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch statamic statamic systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. This has been fixed in 6.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • statamic

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-28); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
statamic

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-02-27: 2Mentions · 2026-02-28: 3Mentions · 2026-03-01: 1Mentions · 2026-03-04: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-01: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 3Technical Details · 2026-03-01: 1Technical Details · 2026-03-04: 102-2702-2803-0103-04
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure1Patch1
2026-02-283
Disclosure3
2026-03-011
Patch1
2026-03-041
Disclosure1
Full discourse7 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27939 (CVSS:8.8, HIGH) is Undergoing Analysis. Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6..https://nvd.nist.gov/vuln/detail/CVE-2026-27939 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-27939 with a high CVSS score for Statmatic CMS, noting it is under analysis but provides no PoC, exploit, or patch details.

    0000039
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Statamic CMS` has an authenticated privilege escalation vulnerability (CVE-2026-27939). Admins should review updates to prevent session bypass. #Statamic #PrivEsc #InfoSec https://www.pulsepatch.io/posts/cve-2026-27939-statamic-cms-privilege-escalation

    Post summary

    Statamic CMS has an authenticated privilege escalation vulnerability (CVE-2026-27939); admins are advised to apply updates to mitigate session bypass.

    0000052
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27939 Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may un… https://www.cve.org/CVERecord?id=CVE-2026-27939

    Post summary

    CVE-2026-27939 is a disclosed vulnerability in Statmatic CMS that allows authenticated Control Panel users to perform an unspecified action between versions 6.0.0 and 6.4.0; no PoC, exploit, or patch information is provided.

    00000134
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27939 Privilege Escalation in Statmatic CMS 6.0.0 to 6.4.0 via Authenti... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27939 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text announces a privilege‑escalation vulnerability (CVE‑2026‑27939) affecting Statmatic CMS 6.0.0‑6.4.0, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000059
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27939: Statamic CMS Privilege Escalation via Antlers Sandbox Escape and Session Bypass A critical privilege escalation vulnerability exists in Statamic CMS versions prior to 6.4.0, allowing authenticated Control Panel users to bypass the 'Ele... https://cvereports.com/reports/CVE-2026-27939

    Post summary

    The post announces a privilege escalation flaw in Statamic CMS that lets authenticated users escape the Antlers sandbox and bypass session checks; it provides technical details but does not mention PoC, exploit code, active attacks, patches, or false positives.

    0000063
    32 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-27939 - High Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions ob... https://www.thehackerwire.com/vulnerability/CVE-2026-27939/ https://t.co/SzDSENUQ6j

    Post summary

    The tweet announces a high‑severity CVE (CVE‑2026‑27939) affecting Statmatic CMS versions 6.0.0–6.4.0, but provides no PoC, exploit code, or patch details.

    0000069
    119 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27939: HIGH] Cyber security alert: Using Statmatic CMS versions 6.0.0 to 6.3.0 could allow for privilege escalation. Update to version 6.4.0 to fix this vulnerability. #cybersecurity#cve,CVE-2026-27939,#cybersecurity https://cvefind.com/CVE-2026-27939

    Post summary

    The post announces a high‑severity privilege escalation flaw in Statmatic CMS (CVE-2026-27939) and recommends upgrading to version 6.4.0 to remediate the issue.

    0000064
    585 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstatamicstatamic---

Explore more