Access Control Vulnerability in Wagtail Content Management System by Wagtail
CVE-2026-55468
4.3MEDIUM
What is CVE-2026-55468?
Wagtail, the open-source content management system built on Django, has a vulnerability in its internal Pages admin API. Versions before 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 lack adequate access control, allowing users with admin privileges to access restricted draft and live page content via api_fields. This flaw poses a risk as it permits unauthorized the retrieval of sensitive information, thus making secure access management essential for users.
Affected Version(s)
wagtail < 7.0.9 < 7.0.9
wagtail >= 7.1, < 7.3.4 < 7.1, 7.3.4
wagtail >= 7.4, < 7.4.3 < 7.4, 7.4.3
