CVE-2026-54244Disclosure

LOWCVSS 3.5 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Controllers/CP/PreviewController.php only checked view authorization, but it accepts and renders caller-supplied field values. A Control Panel user with view but not edit permission could therefore submit content they were not authorized to author and generate a shareable Live Preview URL rendering it. This issue is fixed in versions 5.74.0 and 6.20.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-27: 1Technical Details · 2026-06-27: 106-27
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🔵 Statamic CMS, Incorrect Authorization, #CVE-2026-54244 (Low) -DC-Jun2026-721 https://dailycve.com/statamic-cms-incorrect-authorization-cve-2026-54244-low-dc-jun2026-721/

    Post summary

    The post provides a basic disclosure of CVE‑2026‑54244 in Statamic CMS, labeling it as an incorrect authorization issue with low severity, without details on PoC, exploit tools, or mitigation.

    0000058
    216 followersView on X

Explore more