MEDIUM 4.3 GitHub
CVE-2026-54262
Wagtail: Pages translations can be created without page permissions when using simple_translation
### Impact
A low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for.
### Patches
Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2.
### Workarounds
N/A
### Acknowledgements
Many thanks to @devansh3008 and @alanturing881 for reporting this issue.
### For more information
If you have any questions or comments about this advisory:
* Visit Wagtail's [support channels](https://docs.wagt
Affected Products
- pip/wagtail < 7.0.8
- pip/wagtail >= 7.1, < 7.3.3
- pip/wagtail >= 7.4, < 7.4.2
References
- https://github.com/advisories/GHSA-8634-mr4j-r72c
- https://github.com/wagtail/wagtail/security/advisories/GHSA-8634-mr4j-r72c
- https://nvd.nist.gov/vuln/detail/CVE-2026-54262
- https://github.com/pypa/advisory-database/tree/main/vulns/wagtail/PYSEC-2026-615.yaml
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-20 via GitHub. Affected: pip/wagtail < 7.0.8, pip/wagtail >= 7.1, < 7.3.3, pip/wagtail >= 7.4, < 7.4.2.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.