PT-2026-83661 · Pypi · Wagtail

Published

2026-08-20

·

Updated

2026-08-20

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact

A CMS user with "add" permission over a snippet model, but not "change" or "view" permission, could copy an existing snippet that they do not have access to, allowing them to view its contents.

Patches

Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.

Workarounds

N/A

Acknowledgements

Many thanks to tinyb0y for reporting this issue.

For more information

If you have any questions or comments about this advisory:

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-X5CX-W6P2-MXF2

Affected Products

Wagtail