lowCVSS 3.5Vulnerability

CVE-2026-54244

### Impact The Live Preview endpoint for existing entries and terms only checked view authorization, but it accepts and renders caller-supplied field values. A Control Panel user with view but not edit permission could therefore submit content they were not authorized to author and generate a shareable Live Preview URL rendering it. ### Patches This has been fixed in 5.74.0 and 6.20.3.

Properties

summary
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
severity
low
epss_score
0.00174
cvss_score
3.5
ghsa_published
2026-06-26T23:10:37Z
source_url
https://github.com/advisories/GHSA-7mqq-4v55-88gh
ghsa_updated
2026-06-26T23:10:39Z
ghsa_id
GHSA-7mqq-4v55-88gh
cve_id
CVE-2026-54244
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
is_ghsa_only
false
epss_percentile
0.07

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/statamic/cms

AFFECTS (1)

[Software]composer/statamic/cms

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-54244 (CVSS 3.5) — Ninja Signal Threat Intelligence | Ninja Signal