CVE-2026-27939
HIGH8.8EPSS 0.02%Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
發布日:2026/2/27修改日:2026/3/4
描述
## Impact Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. ## Patches This has been fixed in 6.4.0.
受影響套件(1)
- Packagist/statamic/cms>= 6.0.0, < 6.4.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |