Intel

AIKIDO-2026-10394

statamic/cms is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 19, 2026

40

Medium Risk

This Affects:

PHPstatamic/cms
5.0.0 - 5.73.12
Fixed in 5.73.13
6.0.0 - 6.6.2
Fixed in 6.6.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an improper access control issue in the relationship endpoint. The implementation does not sufficiently enforce authorization checks when retrieving related resources, allowing authenticated users to access data beyond their intended permissions. An attacker could exploit this by querying the endpoint to retrieve restricted or non-public content. The issue is addressed by adding proper authorization validation to ensure that only permitted resources are returned.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

statamic/cms is vulnerable to Improper Access Control in versions 5.0.0 - 5.73.12 and 6.0.0 - 6.6.2.

How to fix this

Upgrade the statamic/cms library to the patch version.