CVE-2026-33886: Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields
Impact A control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content.
Patches This has been fixed in 5.73.16 and 6.7.2.
Other sources
Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33886?
CVE-2026-33886 has a high severity due to the potential exposure of sensitive application configuration values.
How do I fix CVE-2026-33886?
To fix CVE-2026-33886, you need to update your Statamic CMS to version 5.73.16 or 6.7.2.
What software is affected by CVE-2026-33886?
CVE-2026-33886 affects Statamic CMS versions 5.73.12 to 5.73.15 and 6.5.0 to 6.7.1.
Who is impacted by CVE-2026-33886?
Users with control panel access who work with Antlers-enabled fields are impacted by CVE-2026-33886.
Are there any workarounds for CVE-2026-33886?
There are no specific workarounds for CVE-2026-33886; the only solution is to apply the available patches.