Intel

AIKIDO-2026-10749

statamic/cms is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data Authenticity Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 7, 2026

45

Medium Risk

This Affects:

PHPstatamic/cms
4.38.0 - 6.15.0
Fixed in 6.16.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package rely solely on the presence of the Precognition-Validate-Only header to trigger validation-only behavior, without verifying that the request is actually a legitimate precognitive request. This allows an attacker to spoof the header and bypass normal validation and submission logic, potentially preventing required validation rules from executing or altering application flow.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

statamic/cms is vulnerable to Insufficient Verification of Data Authenticity in versions 4.38.0 - 6.15.0.

How to fix this

Upgrade the statamic/cms library to the patch version.