CVE-2026-28424

Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*

History

05 Mar 2026, 14:46

Type Values Removed Values Added
Summary
  • (es) Statmatic es un sistema de gestión de contenidos (CMS) impulsado por Laravel y Git. Antes de las versiones 5.73.11 y 6.4.0, las direcciones de correo electrónico de los usuarios se incluían en las respuestas del endpoint de datos del tipo de campo de usuario para los usuarios del panel de control que no tenían el permiso de 'ver usuarios'. Esto se ha corregido en las versiones 5.73.11 y 6.4.0.
References () https://github.com/statamic/cms/releases/tag/v5.73.11 - () https://github.com/statamic/cms/releases/tag/v5.73.11 - Release Notes
References () https://github.com/statamic/cms/releases/tag/v6.4.0 - () https://github.com/statamic/cms/releases/tag/v6.4.0 - Release Notes
References () https://github.com/statamic/cms/security/advisories/GHSA-w878-f8c6-7r63 - () https://github.com/statamic/cms/security/advisories/GHSA-w878-f8c6-7r63 - Patch, Vendor Advisory
First Time Statamic statamic
Statamic
CPE cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*

27 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 23:16

Updated : 2026-03-05 14:46


NVD link : CVE-2026-28424

Mitre link : CVE-2026-28424

CVE.ORG link : CVE-2026-28424


JSON object : View

Products Affected

statamic

  • statamic
CWE
CWE-862

Missing Authorization