S
tatmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0.
References
| Link | Resource |
|---|---|
| https://github.com/statamic/cms/releases/tag/v5.73.11 | Release Notes |
| https://github.com/statamic/cms/releases/tag/v6.4.0 | Release Notes |
| https://github.com/statamic/cms/security/advisories/GHSA-w878-f8c6-7r63 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
05 Mar 2026, 14:46
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Statamic
Statamic statamic |
|
| Summary |
|
|
| References | () https://github.com/statamic/cms/releases/tag/v5.73.11 - Release Notes | |
| References | () https://github.com/statamic/cms/releases/tag/v6.4.0 - Release Notes | |
| References | () https://github.com/statamic/cms/security/advisories/GHSA-w878-f8c6-7r63 - Patch, Vendor Advisory | |
| CPE | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* |
27 Feb 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-27 23:16
Updated : 2026-03-05 14:46
NVD link : CVE-2026-28424
Mitre link : CVE-2026-28424
CVE.ORG link : CVE-2026-28424
JSON object : View
CWE
CWE-862
Missing Authorization