THREAT OPS › Threat News › [GHSA] GHSA-3vrh-m9w7-v94f (medium) — Wagtail: Improper restriction handling on Pages admin API
[GHSA] GHSA-3vrh-m9w7-v94f (medium) — Wagtail: Improper restriction handling on Pages admin API
GHSA-3vrh-m9w7-v94f Severity: medium CVE: CVE-2026-55468
Wagtail: Improper restriction handling on Pages admin API
### Impact
The internal Pages admin API incorrectly returns page fields without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and l
Indicators of compromise
- CVE-2026-55468cve
- https://docs.wagtail.org/en/stable/advanced_topics/api/index.htmlurl
- https://docs.wagtail.org/en/stable/support.htmlurl
- security@wagtail.orgemail
Original source: https://github.com/advisories/GHSA-3vrh-m9w7-v94f