lowCVSS 3.5Vulnerability
CVE-2026-54244
### Impact The Live Preview endpoint for existing entries and terms only checked view authorization, but it accepts and renders caller-supplied field values. A Control Panel user with view but not edit permission could therefore submit content they were not authorized to author and generate a shareable Live Preview URL rendering it. ### Patches This has been fixed in 5.74.0 and 6.20.3.
Properties
- summary
- Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
- severity
- low
- epss_score
- 0.00174
- cvss_score
- 3.5
- ghsa_published
- 2026-06-26T23:10:37Z
- source_url
- https://github.com/advisories/GHSA-7mqq-4v55-88gh
- ghsa_updated
- 2026-06-26T23:10:39Z
- ghsa_id
- GHSA-7mqq-4v55-88gh
- cve_id
- CVE-2026-54244
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.07
Related Entities (5)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]Incorrect Authorization
REPORTED_BY (1)
→[Source]GitHub Advisory Database
VULNERABLE_TO (1)
←[Software]composer/statamic/cms
AFFECTS (1)
→[Software]composer/statamic/cms
Explore deeper with Ninja Signal's threat intelligence graph