CVE-2026-33886: Statamic

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.

Affected products

  • Statamic Statamic: from 5.73.12, before 5.73.16 (fixed in 5.73.16); from 6.5.0, before 6.7.2 (fixed in 6.7.2)

Published 2026-03-27. Last modified 2026-06-17.