← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 24, 2026 · 20:37via CVEFeed

CVE-2026-55468 - Wagtail: Improper restriction handling on Pages admin API

Brief

CVE ID : CVE-2026-55468

Published : Aug. 24, 2026, 8:37 p. m.

  • 34 minutes ago

Description : Wagtail is an open source content management system built on Django. Prior to versions 7.

  • 9, 7.
  • 4, 7.
  • 3, and 8. 0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.
  • 9, 7.
  • 4, 7.
  • 3, and 8. 0rc2.

Severity: 0.0

  • NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed