Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0.
History

Fri, 27 Feb 2026 22:30:00 +0000

Type Values Removed Values Added
Description Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email addresses were included in responses from the user fieldtype’s data endpoint for control panel users who did not have the "view users" permission. This has been fixed in 5.73.11 and 6.4.0.
Title Statamic's missing authorization allows access to email addresses
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-02-27T22:14:01.779Z

Reserved: 2026-02-27T15:54:05.136Z

Link: CVE-2026-28424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-27T23:16:05.447

Modified: 2026-02-27T23:16:05.447

Link: CVE-2026-28424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.