VYPR
Medium severity4.3NVD Advisory· Published Aug 24, 2026· Updated Sep 9, 2026

CVE-2026-55468

CVE-2026-55468

Description

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
wagtailPyPI
< 7.0.97.0.9
wagtailPyPI
>= 7.1, < 7.3.47.3.4
wagtailPyPI
>= 7.4, < 7.4.37.4.3
wagtailPyPI
>= 8.0rc1, < 8.0rc28.0rc2

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.