CVE-2026-27196: Statamic affected by privilege escalation via stored Cross-site Scripting
Impact
Stored XSS vulnerability in html fieldtypes allow authenticated users with field management permissions to inject malicious JavaScript that executes when viewed by higher-privileged users.
Patches
This has been fixed in 6.3.2 and 5.73.9.
Other sources
Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management permissions to inject malicious JavaScript that executes when viewed by higher-privileged users. This issue has been fixed in 6.3.2 and 5.73.9.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27196?
CVE-2026-27196 is a stored XSS vulnerability that impacts authenticated users with field management permissions allowing potential elevation of privileges.
How do I fix CVE-2026-27196?
To fix CVE-2026-27196, upgrade to Statamic CMS version 6.3.2 or 5.73.9.
Who is affected by CVE-2026-27196?
CVE-2026-27196 affects authenticated users who have field management permissions in Statamic CMS.
What type of vulnerability is CVE-2026-27196?
CVE-2026-27196 is categorized as a stored Cross-Site Scripting (XSS) vulnerability.
When was CVE-2026-27196 disclosed?
CVE-2026-27196 was disclosed as part of a security advisory issued for Statamic CMS.