CVE-2026-33887
Statamic allows unauthorized content access through missing authorization in its revision controllers
5.4
MEDIUM
CVSS 3.1
EPSS 0.14%
描述
### Impact Authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the authorization checks that the main entry controllers enforce, exposing entry field values and blueprint data. Users could also create entry revisions without edit permission, though this only snapshots the existing content state and does not affect published content. ### Patches This has been fixed in 5.73.16 and 6.7.2.
如何修補 CVE-2026-33887
要修補 CVE-2026-33887,請將受影響套件升級到下列已修補版本。
- —升級至 5.73.16 或更新版本
CVE-2026-33887 正在被利用嗎?
低 — EPSS 為 0.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 5.73.16
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |