GHSA-c2xx-cjmh-9q8fMedium· 5.3▾ SunlitWagtail: Improper restriction handling on descendant collections in Documents and Images API
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Documents and Images API V2 incorrectly listed items in descendants of private collections, which should inherit the view restrictions defined on their ancestors. A user with access to the API could see the filename and name of documents and images in these descendant collections.
Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.
Site owners using Wagtail's API can avoid the vulnerability by adding authentication to the Documents and Images APIs.
Many thanks to Ta Duc Thien for reporting this issue.
If you have any questions or comments about this advisory:
wagtail < 7.0.9wagtail >= 7.1, < 7.3.4wagtail >= 7.4, < 7.4.3wagtail = 8.0rc1Upgrade to a patched release:
wagtail 7.0.9wagtail 7.3.4wagtail 7.4.3wagtail 8.0rc2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54259Medium· 4.3Wagtail: Improper restriction handling on Documents and Images chosen endpoints
CVE-2026-54261Medium· 6.5Wagtail: Improper permission handling in image preview
CVE-2026-54262Medium· 4.3Wagtail: Pages translations can be created without page permissions when using simple_translation
CVE-2026-55468Medium· 4.3Wagtail: Improper restriction handling on Pages admin API
GHSA-92hv-j533-69wcLow· 3.7Wagtail: Identification of documents by SHA1 hash
GHSA-x5cx-w6p2-mxf2Medium· 6.5Wagtail: Improper permission handling when copying snippets