MEDIUM 4.3 GitHub

CVE-2026-55468

Wagtail: Improper restriction handling on Pages admin API

### Impact The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`. The vulnerability is not exploitable

Affected Products

References

Published: 2026-08-20 · Source: GitHub · Feed updated: 2026-08-20
This medium severity vulnerability with a CVSS score of 4.3 was published on 2026-08-20 via GitHub. Affected: pip/wagtail < 7.0.9, pip/wagtail >= 7.1, < 7.3.4, pip/wagtail >= 7.4, < 7.4.3 and 1 more.
vulnfeed aggregates 11796 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.