Access Control Vulnerability in Wagtail Content Management System by Wagtail
CVE-2026-55468

4.3MEDIUM

Key Information:

Vendor

Wagtail

Status
Vendor
CVE Published:
24 August 2026

What is CVE-2026-55468?

Wagtail, the open-source content management system built on Django, has a vulnerability in its internal Pages admin API. Versions before 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 lack adequate access control, allowing users with admin privileges to access restricted draft and live page content via api_fields. This flaw poses a risk as it permits unauthorized the retrieval of sensitive information, thus making secure access management essential for users.

Affected Version(s)

wagtail < 7.0.9 < 7.0.9

wagtail >= 7.1, < 7.3.4 < 7.1, 7.3.4

wagtail >= 7.4, < 7.4.3 < 7.4, 7.4.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.