THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x5cx-w6p2-mxf2 (medium) — Wagtail: Improper permission handling when copying snippets

[GHSA] GHSA-x5cx-w6p2-mxf2 (medium) — Wagtail: Improper permission handling when copying snippets

highgithub_advisoriesPublished 2026-08-20

GHSA-x5cx-w6p2-mxf2 Severity: medium CVE: None

Wagtail: Improper permission handling when copying snippets

### Impact A CMS user with "add" permission over a snippet model, but not "change" or "view" permission, could copy an existing snippet that they do not have access to, allowing them to view its contents.

### Patches Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x5cx-w6p2-mxf2