CVE-2026-33177Exploit(statamic / statamic)

MEDIUMCVSS 4.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch statamic statamic systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileged Control Panel users could create taxonomy terms by submitting requests to the field action processing endpoint with attacker-controlled field definitions. This bypasses the authorization checks enforced on the standard taxonomy term creation endpoint. This has been fixed in 5.73.14 and 6.7.0.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • statamic

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
statamic

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1PoC Mentioned / Linked · 2026-03-20: 1Active Exploitation · 2026-03-20: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 103-2003-21
Signal classification3 categories
Exploit
133.3%
General
133.3%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-202
Exploit1General1
2026-03-211
Patch1
Full discourse3 posts
  • Yassin Mohamed 🇵🇸@0xblackkk
    Exploit

    I got 3 CVEs: CVE-2026-27593: Patched before, but still exploitable. Achieved Admin Account Takeover. CVE-2026-4420: Stored XSS → chained → 1-click Account Takeover CVE-2026-33177: Broken Access Control via alternative controller bypass. Full writeups in comments. https://t.co/zLP0GVo4kY

    Post summary

    Three CVEs (CVE-2026-27593, CVE-2026-4420, CVE-2026-33177) have been reported as still exploitable despite prior patches, enabling admin or account takeovers; full writeups and probable PoC are available via the provided link.

    212070305.2K
    119 followersView on X
  • Yassin Mohamed 🇵🇸@0xblackkk
    General

    CVE-2026-27593 (Critical) https://everythingblackkk.gitbook.io/everythingblackkk/my-cve/cve-2026-27593-critical CVE-2026-33177 (Moderate) https://everythingblackkk.gitbook.io/everythingblackkk/my-cve/cve-2026-33177-moderate CVE-2026-4420 (Moderate) https://youtu.be/B5F-tYDHi_I

    Post summary

    The text lists three CVE identifiers with severity labels and provides URLs, but it offers no technical details, PoC, exploit code, or other actionable information.

    01076630
    119 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-33177 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileged Control Panel users could create taxonomy t… https://www.cve.org/CVERecord?id=CVE-2026-33177

    Post summary

    CVE‑2026‑33177 allows low‑privileged Control Panel users to create taxonomy entries in Statamic before versions 5.73.14 and 6.7.0, and upgrading to those versions mitigates the vulnerability.

    00000135
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstatamicstatamic---

Explore more