GHSA-qh8c-7588-qfrvMediumCVSS 6.5

Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

Published
August 6, 2026
Last Modified
August 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated Control Panel user could view content from entries they don't have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.

Patches

This has been fixed in 5.74.1 and 6.24.0.

🎯 Affected products2

  • composer/statamic/cms:< 5.74.1
  • composer/statamic/cms:>= 6.0.0, < 6.24.0

🔗 References (6)