THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vgxm-h9gx-h9w7 (medium) — django CMS: Structure endpoint bypasses page-view permission

[GHSA] GHSA-vgxm-h9gx-h9w7 (medium) — django CMS: Structure endpoint bypasses page-view permission

medgithub_advisoriesPublished 2026-08-20

GHSA-vgxm-h9gx-h9w7 Severity: medium CVE: CVE-2026-54624

django CMS: Structure endpoint bypasses page-view permission

### Summary The structure-board endpoint (`render_object_structure`) renders a page's plugin structure without verifying that the requesting user is allowed to view the page. The edit and preview endpoints enforce this via `render_page()`, but the structure endpoint does not, all

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vgxm-h9gx-h9w7