Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass
Description
Published to the GitHub Advisory Database
Feb 27, 2026
Reviewed
Feb 27, 2026
Last updated
Feb 27, 2026
Impact
Authenticated Control Panel users may under certain conditions obtain elevated privileges without completing the intended verification step. This can allow access to sensitive operations and, depending on the user’s existing permissions, may lead to privilege escalation.
Patches
This has been fixed in 6.4.0.
References