Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gwmx-9gcj-332h | Statamic CMS's missing authorization allows access to assets |
Wed, 18 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic statamic
|
|
| CPEs | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Statamic statamic
|
Thu, 12 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Statamic
Statamic cms |
|
| Vendors & Products |
Statamic
Statamic cms |
Wed, 11 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5. | |
| Title | Statamic's missing authorization allows access to assets | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-12T21:19:37.486Z
Reserved: 2026-02-04T05:15:41.790Z
Link: CVE-2026-25633
Updated: 2026-02-12T21:19:34.949Z
Status : Analyzed
Published: 2026-02-11T21:16:18.910
Modified: 2026-02-18T19:36:44.100
Link: CVE-2026-25633
No data.
OpenCVE Enrichment
Updated: 2026-04-17T20:15:27Z
Github GHSA