CVE-2026-27939: Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-27939 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →