6.5
CVE-2026-28424
- EPSS 0.23%
- Veröffentlicht 27.02.2026 22:14:01
- Zuletzt bearbeitet 05.03.2026 14:46:10
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Statamic's missing authorization allows access to email addresses
Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.136 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/statamic/cms/releases/tag/v5.73.11
https://github.com/statamic/cms/releases/tag/v6.4.0
https://github.com/statamic/cms/security/advisories/GHSA-w878-f8c6-7r63