4.3

CVE-2026-55468

Wagtail: Improper restriction handling on Pages admin API

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerwagtail
≫
Produkt wagtail
Version < 7.0.9
Status affected
Version >= 7.1, < 7.3.4
Status affected
Version >= 7.4, < 7.4.3
Status affected
Version >= 8.0rc1, < 8.0rc2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-280 Improper Handling of Insufficient Permissions or Privileges

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

https://github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94f
https://github.com/wagtail/wagtail/commit/5608cfb714a130412f862beab53c78de02b79975
https://github.com/wagtail/wagtail/commit/aef935530d5289406ca325b42747af15f3b28ac4
https://github.com/wagtail/wagtail/commit/d99d2bec2b0aca46d88014416432c717240cd559
https://github.com/wagtail/wagtail/commit/e2fa629b7a51ec29d59e45eead930feee0d3c4b3