CVE-2026-64662: Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
An authenticated Control Panel user could view content from entries they don’t have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.
References
- github.com/advisories/GHSA-qh8c-7588-qfrv
- github.com/statamic/cms/commit/6557f1d8a0d61c0e7ad9c9a8f42cb3288607495d
- github.com/statamic/cms/pull/14906
- github.com/statamic/cms/releases/tag/v5.74.1
- github.com/statamic/cms/releases/tag/v6.24.0
- github.com/statamic/cms/security/advisories/GHSA-qh8c-7588-qfrv
- nvd.nist.gov/vuln/detail/CVE-2026-64662
Code Behaviors & Features
Detect and mitigate CVE-2026-64662 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →