All vulnerabilities

CVE-2026-64662

Packagist · statamic/cms

Summary

Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

Advisory details

Impact

An authenticated Control Panel user could view content from entries they don't have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.

Patches

This has been fixed in 5.74.1 and 6.24.0.

References