CVE-2026-54262Medium· 4.3▾ SunlitWagtail: Pages translations can be created without page permissions when using simple_translation
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.3%
A low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for.
Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2.
N/A
Many thanks to @devansh3008 and @alanturing881 for reporting this issue.
If you have any questions or comments about this advisory:
wagtail < 7.0.8wagtail >= 7.1, < 7.3.3wagtail >= 7.4, < 7.4.2Upgrade to a patched release:
wagtail 7.0.8wagtail 7.3.3wagtail 7.4.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54259Medium· 4.3Wagtail: Improper restriction handling on Documents and Images chosen endpoints
CVE-2026-54261Medium· 6.5Wagtail: Improper permission handling in image preview
CVE-2026-55468Medium· 4.3Wagtail: Improper restriction handling on Pages admin API
GHSA-92hv-j533-69wcLow· 3.7Wagtail: Identification of documents by SHA1 hash
GHSA-c2xx-cjmh-9q8fMedium· 5.3Wagtail: Improper restriction handling on descendant collections in Documents and Images API
GHSA-x5cx-w6p2-mxf2Medium· 6.5Wagtail: Improper permission handling when copying snippets