Medium severity4.3NVD Advisory· Published Aug 24, 2026· Updated Sep 9, 2026
CVE-2026-55468
CVE-2026-55468
Description
Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wagtailPyPI | < 7.0.9 | 7.0.9 |
wagtailPyPI | >= 7.1, < 7.3.4 | 7.3.4 |
wagtailPyPI | >= 7.4, < 7.4.3 | 7.4.3 |
wagtailPyPI | >= 8.0rc1, < 8.0rc2 | 8.0rc2 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-3vrh-m9w7-v94fghsaADVISORY
- github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94fnvdWEB
- github.com/wagtail/wagtail/commit/5608cfb714a130412f862beab53c78de02b79975nvd
- github.com/wagtail/wagtail/commit/aef935530d5289406ca325b42747af15f3b28ac4nvd
- github.com/wagtail/wagtail/commit/d99d2bec2b0aca46d88014416432c717240cd559nvd
- github.com/wagtail/wagtail/commit/e2fa629b7a51ec29d59e45eead930feee0d3c4b3nvd
News mentions
0No linked articles in our index yet.