CVE-2026-33884: Statamic's live preview token bypasses content protection for unrelated entries
Impact An authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for.
Patches This has been fixed in 5.73.16 and 6.7.2.
Other sources
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16 and 6.7.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33884?
CVE-2026-33884 is classified as a high severity vulnerability due to its potential to allow authenticated users to bypass content restrictions.
How do I fix CVE-2026-33884?
To fix CVE-2026-33884, upgrade to Statamic CMS version 5.73.16 or later, or to 6.7.2.
Who is affected by CVE-2026-33884?
CVE-2026-33884 affects authenticated users with access to the live preview feature in Statamic CMS.
What is the impact of CVE-2026-33884?
The impact of CVE-2026-33884 is that it allows users to access restricted content through a live preview token unintended for their use.
Is there a workaround for CVE-2026-33884 while awaiting a patch?
There is no known effective workaround for CVE-2026-33884 aside from applying the recommended software updates.