Improper Access Control in Django-Page-CMS by Batiste
CVE-2026-93455
7.1HIGH
What is CVE-2026-93455?
Django-Page-CMS up to version 2.0.13 contains a flaw that allows staff accounts to bypass intended access controls. This vulnerability enables unauthorized users to read arbitrary page content and access stored media paths. Low-privilege staff members can enumerate content identifiers, gaining access to unpublished drafts, page listings, and file paths without appropriate authorization checks, posing a risk to sensitive information.
Affected Version(s)
django-page-cms 0 <= 2.0.13
