CVE-2026-33886

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their content. This has been fixed in 5.73.16 and 6.7.2.
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-27 21:17

Updated : 2026-03-30 13:26


NVD link : CVE-2026-33886

Mitre link : CVE-2026-33886

CVE.ORG link : CVE-2026-33886


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor