---
id: CVE-2026-55468
aliases:
  - GHSA-3vrh-m9w7-v94f
  - PYSEC-2026-3939
title: 'Wagtail: Improper restriction handling on Pages admin API'
summary: 'Wagtail: Improper restriction handling on Pages admin API'
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
vendor: wagtail
product: wagtail
ecosystem: pip
affected:
  - wagtail < 7.0.9
  - 'wagtail >= 7.1, < 7.3.4'
  - 'wagtail >= 7.4, < 7.4.3'
  - 'wagtail >= 8.0rc1, < 8.0rc2'
patched:
  - wagtail 7.0.9
  - wagtail 7.3.4
  - wagtail 7.4.3
  - wagtail 8.0rc2
published: '2026-08-20'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T12:25:53.019416386Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-3vrh-m9w7-v94f'
references:
  - url: 'https://github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94f'
  - url: 'https://github.com/wagtail/wagtail'
  - url: 'https://pypi.org/project/wagtail'
  - url: 'https://github.com/advisories/GHSA-3vrh-m9w7-v94f'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55468'
  - url: >-
      https://github.com/wagtail/wagtail/commit/5608cfb714a130412f862beab53c78de02b79975
    label: security-advisories@github.com
  - url: >-
      https://github.com/wagtail/wagtail/commit/aef935530d5289406ca325b42747af15f3b28ac4
    label: security-advisories@github.com
  - url: >-
      https://github.com/wagtail/wagtail/commit/d99d2bec2b0aca46d88014416432c717240cd559
    label: security-advisories@github.com
  - url: >-
      https://github.com/wagtail/wagtail/commit/e2fa629b7a51ec29d59e45eead930feee0d3c4b3
    label: security-advisories@github.com
tags:
  - osv
  - pip
  - nvd
  - ghsa
epss: 0.00342
epssPercentile: 0.24942
cwe:
  - CWE-280
ingestedAt: '2026-08-20T18:59:54.274Z'
---

## Overview

### Impact

The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields  without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`.

The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.

### Patches

Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.

### Workarounds

Site owners unable to upgrade can apply the fix by overriding the relevant method on `PagesAdminAPIViewSet` to patch all vulnerable admin API endpoints:

```python
# wagtail_hooks.py or AppConfig.ready()

from wagtail.admin.api.views import PagesAdminAPIViewSet
from wagtail.permissions import page_permission_policy


def _restricted_get_base_queryset(self):
    return page_permission_policy.explorable_instances(self.request.user)

PagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset
```

### Acknowledgements

Many thanks to xuliang@QAX for reporting this issue.

### For more information

If you have any questions or comments about this advisory:

-   Visit Wagtail's [support channels](https://docs.wagtail.org/en/stable/support.html)
-   Email us at [security@wagtail.org](mailto:security@wagtail.org) (view our [security policy](https://github.com/wagtail/wagtail/security/policy) for more information).

## Affected packages

- `wagtail < 7.0.9`
- `wagtail >= 7.1, < 7.3.4`
- `wagtail >= 7.4, < 7.4.3`
- `wagtail >= 8.0rc1, < 8.0rc2`

## Remediation

Upgrade to a patched release:

- `wagtail 7.0.9`
- `wagtail 7.3.4`
- `wagtail 7.4.3`
- `wagtail 8.0rc2`
