CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-55468

mediumCVSS 4.3covered by 2 sourcesfirst seen 2026-08-20
Impact The internal Pages admin API incorrectly returns page fields without access control when they are declared in api_fields. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of api_fields on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in api_fields. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. Patches Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2. Workarounds Site owners unable to upgrade can apply the fix by overriding the relevant method on PagesAdminAPIViewSet to patch all vulnerable admin API endpoints: wagtail_hooks.py or AppConfig.ready() from wagtail.admin.api.views import PagesAdminAPIViewSet from wagtail.permissions import page_permission_policy def _restricted_get_base_queryset(self): return page_permission_policy.explorable_instances(self.request.user) PagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset Acknowledgements Many thanks to xuliang@QAX for reporting this issue. For more information If you have any questions or comments about this advisory: - Visit Wagtail's support channels - Email us at security@wagtail.org (view our security policy for more information).

⚡ Watch CVE-2026-55468

Get an email if CVE-2026-55468 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-55468

CVE.org record

Embed the live status

CVE-2026-55468 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-55468 status](https://www.csirts.com/badge/CVE-2026-55468)](https://www.csirts.com/cve/CVE-2026-55468)