CVE-2026-55468 - Wagtail: Improper restriction handling on Pages admin API
Brief
CVE ID : CVE-2026-55468
Published : Aug. 24, 2026, 8:37 p. m.
- 34 minutes ago
Description : Wagtail is an open source content management system built on Django. Prior to versions 7.
- 9, 7.
- 4, 7.
- 3, and 8. 0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.
- 9, 7.
- 4, 7.
- 3, and 8. 0rc2.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
