Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0.
References
| Link | Resource |
|---|---|
| https://github.com/statamic/cms/releases/tag/v5.73.11 | Release Notes |
| https://github.com/statamic/cms/releases/tag/v6.4.0 | Release Notes |
| https://github.com/statamic/cms/security/advisories/GHSA-w878-f8c6-7r63 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
05 Mar 2026, 14:46
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References | () https://github.com/statamic/cms/releases/tag/v5.73.11 - Release Notes | |
| References | () https://github.com/statamic/cms/releases/tag/v6.4.0 - Release Notes | |
| References | () https://github.com/statamic/cms/security/advisories/GHSA-w878-f8c6-7r63 - Patch, Vendor Advisory | |
| First Time |
Statamic statamic
Statamic |
|
| CPE | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* |
27 Feb 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-27 23:16
Updated : 2026-03-05 14:46
NVD link : CVE-2026-28424
Mitre link : CVE-2026-28424
CVE.ORG link : CVE-2026-28424
JSON object : View
Products Affected
statamic
- statamic
CWE
CWE-862
Missing Authorization
