Impact
Statamic’s navigation endpoint lacked proper authorization checks, allowing authenticated Control Panel users to view content from entries they were not permitted to see. The flaw permits exposure of entry content, custom field values, and even unpublished entries across any collection, though it does not grant the ability to modify data. Consequently, the primary effect is the disclosure of sensitive or restricted information.
Affected Systems
The vulnerability affects the Statamic content management system (statamic:cms) for all releases prior to version 5.74.1 in the 5.x line and prior to 6.24.0 in the 6.x line. Any system running those releases with Control Panel access is subject to this issue.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity, and the EPSS score is not available while the vulnerability is not listed in CISA KEV. The likely attack vector requires an authenticated Control Panel session; once authenticated, an adversary can enumerate and retrieve restricted entries across collections without additional privileges. The risk is therefore moderate to high for environments where data confidentiality is critical.
OpenCVE Enrichment
Github GHSA