PT-2026-80213 · Pypi · Wagtail

Publicado

2026-08-20

·

Atualizado

2026-08-20

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Impact

The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced topics/api/index.html) incorrectly returns page fields without access control when they are declared in api fields. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of api fields on the base page model (title, slug, seo title, search description), as well as all custom fields declared in api fields.
The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.

Patches

Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.

Workarounds

Site owners unable to upgrade can apply the fix by overriding the relevant method on PagesAdminAPIViewSet to patch all vulnerable admin API endpoints:
python
# wagtail hooks.py or AppConfig.ready()

from wagtail.admin.api.views import PagesAdminAPIViewSet
from wagtail.permissions import page permission policy


def restricted get base queryset(self):
  return page permission policy.explorable instances(self.request.user)

PagesAdminAPIViewSet.get base queryset = restricted get base queryset

Acknowledgements

Many thanks to xuliang@QAX for reporting this issue.

For more information

If you have any questions or comments about this advisory:

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-3VRH-M9W7-V94F

Produtos afetados

Wagtail