PatchSiren cyber security CVE debrief
CVE-2026-55468 wagtail CVE debrief
A vulnerability in Wagtail, an open-source content management system, allows users with Wagtail admin access to retrieve restricted draft and live page content via the internal Pages admin API without sufficient access control. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2. The vulnerability impacts content confidentiality, as unauthorized users can access sensitive information. Defenders should prioritize verifying exposure and applying patches to prevent unauthorized content retrieval.
- Vendor
- wagtail
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-24
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-24
- Advisory updated
- 2026-09-09
Who should care
Wagtail administrators and users with access to the Pages admin API should verify exposure and apply patches to prevent unauthorized content retrieval. This includes reviewing compensating controls, monitoring for exposed assets, and tracking exceptions. Content confidentiality is at risk, and defenders should prioritize verifying exposure and applying patches.
Why it matters
Defenders should prioritize verifying exposure and applying patches to prevent unauthorized content retrieval in Wagtail installations.
- Potential unauthorized retrieval of restricted draft and live page content.
- Need to verify exposure and apply patches to prevent content retrieval.
- Possible impact on content confidentiality.
Technical summary
The internal Pages admin API in Wagtail returns page fields declared in api_fields without sufficient access control, allowing users with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2. The vulnerability impacts content confidentiality and requires defenders to verify exposure and apply patches to prevent unauthorized content retrieval. Technical details are limited to public sources and may not be comprehensive. Defenders should prioritize verifying exposure and applying patches.
Defensive priority
Defenders should prioritize verifying exposure and applying patches to prevent unauthorized content retrieval.
Recommended defensive actions
- Verify exposure by checking if the installed Wagtail version is prior to 7.0.9, 7.3.4, 7.4.3, or 8.0rc2.
- Apply patches by upgrading to Wagtail versions 7.0.9, 7.3.4, 7.4.3, or 8.0rc2.
- Restrict access to the Pages admin API to prevent unauthorized content retrieval.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and fixed versions. The internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing users with Wagtail admin access to retrieve restricted draft and live page content. Evidence is limited to public sources and may not be comprehensive. Defenders should verify exposure and apply patches to prevent unauthorized content retrieval.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55468 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55468
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55468 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55468
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wagtail/wagtail/commit/5608cfb714a130412f862beab53c78de02b79975
-
Source reference
Unverified legacy reference
URL: https://github.com/wagtail/wagtail/commit/aef935530d5289406ca325b42747af15f3b28ac4
-
Source reference
Unverified legacy reference
URL: https://github.com/wagtail/wagtail/commit/d99d2bec2b0aca46d88014416432c717240cd559
-
Source reference
Unverified legacy reference
URL: https://github.com/wagtail/wagtail/commit/e2fa629b7a51ec29d59e45eead930feee0d3c4b3
-
Source reference
Unverified legacy reference
URL: https://github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94f
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.