CVE-2026-27939
Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
8.8
HIGH
CVSS 3.1
EPSS 0.02%
Description
## Impact Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation. ## Patches This has been fixed in 6.4.0.
How to fix CVE-2026-27939
To remediate CVE-2026-27939, upgrade the affected package to a fixed version below.
- —upgrade to 6.4.0 or later
Is CVE-2026-27939 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 6.0.0, < 6.4.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |