CVE-2026-55468

medium

Description

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.

References

https://github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94f

https://github.com/wagtail/wagtail/commit/e2fa629b7a51ec29d59e45eead930feee0d3c4b3

https://github.com/wagtail/wagtail/commit/d99d2bec2b0aca46d88014416432c717240cd559

https://github.com/wagtail/wagtail/commit/aef935530d5289406ca325b42747af15f3b28ac4

https://github.com/wagtail/wagtail/commit/5608cfb714a130412f862beab53c78de02b79975

Details

Source: Mitre, NVD

Published: 2026-08-24

Updated: 2026-09-09

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.002