Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41175

29
FAUCET Score

OVERVIEW CVE-2026-41175 affects Statamic, a Laravel and Git-powered content management system, in versions prior to 5.73.20 and 6.13.0. The vulnerability allows attackers to manipulate query parameters on Control Panel and REST API endpoints, as well as arguments in GraphQL queries, resulting in unauthorized deletion of content, assets, and user accounts. The Control Panel exploitation requires minimal authenticated permissions, while REST and GraphQL API exploitation requires no permissions but depends on these interfaces being explicitly enabled without authentication. SEVERITY The vulnerability carries a CVSS score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and low privileges. The attack requires user interaction to be disabled and impacts system integrity and availability through high-impact data destruction. The threat is particularly critical for organizations that have enabled REST or GraphQL APIs without authentication controls, as these endpoints bypass the authentication requirement entirely. EXPLOITATION STATUS There is no evidence of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on the Hot List. The EPSS score of 0.00049 indicates extremely low probability of exploitation in the wild relative to other CVEs. However, organizations should prioritize patching if REST or GraphQL APIs are exposed without authentication, as the attack method is straightforward once these conditions are met.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.73.20CPE matchmatch criteria
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*
>= 6.0.0, < 6.13.0CPE matchmatch criteria
cpe:2.3:a:statamic:statamic:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 10th percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

composerpatch availablevia ghsa
Product: statamic/cmsFixed in: 5.73.20
composerpatch availablevia ghsa
Product: statamic/cmsFixed in: 6.13.0
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-4jjr-vmv7-wh4whigh

Statamic: Unsafe method invocation via query value resolution allows data destruction

Apr 16, 2026

References

github.com / statamic/cms/security/advisories/GHSA-4jjr-vmv7-wh4w
Vendor Advisory