OVERVIEW CVE-2026-41175 affects Statamic, a Laravel and Git-powered content management system, in versions prior to 5.73.20 and 6.13.0. The vulnerability allows attackers to manipulate query parameters on Control Panel and REST API endpoints, as well as arguments in GraphQL queries, resulting in unauthorized deletion of content, assets, and user accounts. The Control Panel exploitation requires minimal authenticated permissions, while REST and GraphQL API exploitation requires no permissions but depends on these interfaces being explicitly enabled without authentication. SEVERITY The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and low privileges. The attack requires user interaction to be disabled and impacts system integrity and availability through high-impact data destruction. The threat is particularly critical for organizations that have enabled REST or GraphQL APIs without authentication controls, as these endpoints bypass the authentication requirement entirely. EXPLOITATION STATUS There is no evidence of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on the Hot List. The EPSS score of 0.00049 indicates extremely low probability of exploitation in the wild relative to other CVEs. However, organizations should prioritize patching if REST or GraphQL APIs are exposed without authentication, as the attack method is straightforward once these conditions are met.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.73.20CPE matchmatch criteria | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.13.0CPE matchmatch criteria | cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.