Improper Access Control in Django-Page-CMS by Batiste
CVE-2026-93455

7.1HIGH

Key Information:

Vendor

Batiste

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93455?

Django-Page-CMS up to version 2.0.13 contains a flaw that allows staff accounts to bypass intended access controls. This vulnerability enables unauthorized users to read arbitrary page content and access stored media paths. Low-privilege staff members can enumerate content identifiers, gaining access to unpublished drafts, page listings, and file paths without appropriate authorization checks, posing a risk to sensitive information.

Affected Version(s)

django-page-cms 0 <= 2.0.13

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.