CVE-2026-55468CWE-280

CVE-2026-55468

Medium · published August 25, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
9.8
In the wild
Unconfirmed
What it is

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00200 · 9.8th percentile
Weakness
CWE-280 · Improper Handling of Insufficient Permissions or Privileges
Published
2026-08-25T01:17Z
References (5)
EPSS history
Timeline
  • 26 AUG 08:14Z
    EPSS moved — → 0%
    epss
  • 24 AUG 20:37Z
    Wagtail: Improper restriction handling on Pages admin API
    cvelistv5