CVE-2026-41175General(statamic / statamic)

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch statamic statamic systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in GraphQL queries, could result in the loss of content, assets, and user accounts. The Control Panel requires authentication with minimal permissions in order to exploit. e.g. "view entries" permission to delete entries, or "view users" permission to delete users, etc. The REST and GraphQL API exploits do not require any permissions, however neither are enabled by default. In order to be exploited, they would need to be explicitly enabled with no authentication configured, and the specific resources enabled too. Sites that enable the REST or GraphQL API without authentication should treat patching as critical priority. This has been fixed in 5.73.20 and 6.13.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-470

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • statamic

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-06-21)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
statamic

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-23: 1Mentions · 2026-06-21: 3Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-06-21: 1Technical Details · 2026-04-23: 1Technical Details · 2026-06-21: 104-2306-21
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-231
Disclosure1
2026-06-213
General2Patch1
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-49287 - Supply chain risk in #Statamic. Unaddressed incomplete fix from CVE-2026-41175. Sort param manipulation could delete content/assets. #CVSS 7.4. No patch; review templates immediately. #CVEAlert #infosec #cybersecurity more FREE info: https://www.valtersit.com/cve/CVE-2026-49287/

    Post summary

    The tweet announces a new CVE in Statamic, highlights an unpatched supply chain risk that allows parameter manipulation to delete content or assets, and urges immediate review of templates despite no patch being available.

    0000071
    953 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-49287 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It addressed the issue … https://www.cve.org/CVERecord?id=CVE-2026-49287 ----- Traducción: CVE-2026-49287 Sta… http://infoflow.cloud`

    Post summary

    The tweet briefly references CVE‑2026‑49287 and links to the CVE record, but provides no additional details, evidence of exploitation, or mitigation instructions.

    0000050
    88 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-49287 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026-41175 was incomplete. It addressed the issue … https://www.cve.org/CVERecord?id=CVE-2026-49287

    Post summary

    The statement merely references CVE-2026-49287 and links to its CVE record, and notes an incomplete fix for a different CVE, without providing further details or actionable information.

    00000316
    57.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41175 Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST A… https://www.cve.org/CVERecord?id=CVE-2026-41175

    Post summary

    The passage announces CVE‑2026‑41175 for Statamic CMS, noting that versions prior to 5.73.20 and 6.13.0 are vulnerable to query‑parameter manipulation; these versions provide the available patch.

    00000108
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstatamicstatamic---

Explore more