THREAT OPS › Threat News › [GHSA] GHSA-qh8c-7588-qfrv (medium) — Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
[GHSA] GHSA-qh8c-7588-qfrv (medium) — Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
GHSA-qh8c-7588-qfrv Severity: medium CVE: CVE-2026-64662
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
### Impact
An authenticated Control Panel user could view content from entries they don't have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.
MITRE ATT&CK techniques
- Control PanelT1218.002
Indicators of compromise
- CVE-2026-64662cve
Original source: https://github.com/advisories/GHSA-qh8c-7588-qfrv