4.3

CVE-2026-25633

Statamic's missing authorization allows access to assets

Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
StatamicStatamic Version < 5.73.6
StatamicStatamic Version >= 6.0.0 < 6.2.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.2
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://github.com/statamic/cms/security/advisories/GHSA-gwmx-9gcj-332h
Vendor Advisory
https://github.com/statamic/cms/commit/5a6f47246edf3a0c453727ffecbfa14333a6bc8a
Patch
Product
https://github.com/statamic/cms/releases/tag/v5.73.6
Release Notes
https://github.com/statamic/cms/releases/tag/v6.2.5
Release Notes