CVE-2026-55468
Wagtail: Improper restriction handling on Pages admin API
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.
| CWE | CWE-280 |
| Vendor | wagtail |
| Product | wagtail |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for wagtail wagtail
Be the first to know when new medium vulnerabilities affecting wagtail wagtail are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
wagtail / wagtail
< 7.0.9 >= 7.1, < 7.3.4 >= 7.4, < 7.4.3 >= 8.0rc1, < 8.0rc2
References
github.com: https://github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94f github.com: https://github.com/wagtail/wagtail/commit/5608cfb714a130412f862beab53c78de02b79975 github.com: https://github.com/wagtail/wagtail/commit/aef935530d5289406ca325b42747af15f3b28ac4 github.com: https://github.com/wagtail/wagtail/commit/d99d2bec2b0aca46d88014416432c717240cd559 github.com: https://github.com/wagtail/wagtail/commit/e2fa629b7a51ec29d59e45eead930feee0d3c4b3