THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3vrh-m9w7-v94f (medium) — Wagtail: Improper restriction handling on Pages admin API

[GHSA] GHSA-3vrh-m9w7-v94f (medium) — Wagtail: Improper restriction handling on Pages admin API

highgithub_advisoriesPublished 2026-08-20

GHSA-3vrh-m9w7-v94f Severity: medium CVE: CVE-2026-55468

Wagtail: Improper restriction handling on Pages admin API

### Impact

The internal Pages admin API incorrectly returns page fields without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and l

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3vrh-m9w7-v94f