Résumé
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
Détails de l’avis
Impact
An authenticated Control Panel user could view content from entries they don't have permission to view, including entry content and custom field values, from any collection and including unpublished entries. No data could be modified.
Patches
This has been fixed in 5.74.1 and 6.24.0.
Références
- https://github.com/advisories/GHSA-qh8c-7588-qfrv
- https://github.com/statamic/cms/security/advisories/GHSA-qh8c-7588-qfrv
- https://github.com/statamic/cms/pull/14906
- https://github.com/statamic/cms/commit/6557f1d8a0d61c0e7ad9c9a8f42cb3288607495d
- https://github.com/statamic/cms/releases/tag/v5.74.1
- https://github.com/statamic/cms/releases/tag/v6.24.0
Vulnérabilités liées
Tout Supply chain →- HIGHCVE-2026-63735
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
- MEDIUMCVE-2026-63669
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
- HIGHCVE-2026-81892
EasyAdmin custom-action dispatcher bypasses access_control on other routes
- MEDIUMCVE-2026-54746
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe
- MEDIUMCVE-2026-61663
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
- MEDIUMCVE-2026-63003
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)