MEDIUM 4.3 GitHub
CVE-2026-55468
Wagtail: Improper restriction handling on Pages admin API
### Impact
The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`.
The vulnerability is not exploitable
Affected Products
- pip/wagtail < 7.0.9
- pip/wagtail >= 7.1, < 7.3.4
- pip/wagtail >= 7.4, < 7.4.3
- pip/wagtail = 8.0rc1
References
- https://github.com/advisories/GHSA-3vrh-m9w7-v94f
- https://github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94f
- https://github.com/advisories/GHSA-3vrh-m9w7-v94f
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-20 via GitHub. Affected: pip/wagtail < 7.0.9, pip/wagtail >= 7.1, < 7.3.4, pip/wagtail >= 7.4, < 7.4.3 and 1 more.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.