THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qh8c-7588-qfrv (medium) — Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

[GHSA] GHSA-qh8c-7588-qfrv (medium) — Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

medgithub_advisoriesPublished 2026-08-06

GHSA-qh8c-7588-qfrv Severity: medium CVE: CVE-2026-64662

Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

### Impact

An authenticated Control Panel user could view content from entries they don't have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qh8c-7588-qfrv