CVE-2026-27939: Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
Impact
Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation.
Patches This has been fixed in 6.4.0.
Other sources
Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6.4.0, Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. This has been fixed in 6.4.0.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27939?
CVE-2026-27939 has been classified as having a significant impact due to the potential for unauthorized privilege escalation.
How do I fix CVE-2026-27939?
To remediate CVE-2026-27939, upgrade Statamic to version 6.4.0 or later.
Who is affected by CVE-2026-27939?
Authenticated Control Panel users of Statamic versions between 6.0.0 and 6.4.0 are affected by CVE-2026-27939.
What actions can be done due to CVE-2026-27939?
An attacker exploiting CVE-2026-27939 can gain elevated privileges and access sensitive operations without proper verification.
When was CVE-2026-27939 disclosed?
CVE-2026-27939 was disclosed in the context of security advisories related to Statamic CMS.