GHSA-x5cx-w6p2-mxf2Medium· 6.5▾ SunlitWagtail: Improper permission handling when copying snippets
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A CMS user with "add" permission over a snippet model, but not "change" or "view" permission, could copy an existing snippet that they do not have access to, allowing them to view its contents.
Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.
N/A
Many thanks to tinyb0y for reporting this issue.
If you have any questions or comments about this advisory:
wagtail < 7.0.9wagtail >= 7.1, < 7.3.4wagtail >= 7.4, < 7.4.3wagtail = 8.0rc1Upgrade to a patched release:
wagtail 7.0.9wagtail 7.3.4wagtail 7.4.3wagtail 8.0rc2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54259Medium· 4.3Wagtail: Improper restriction handling on Documents and Images chosen endpoints
CVE-2026-54261Medium· 6.5Wagtail: Improper permission handling in image preview
CVE-2026-54262Medium· 4.3Wagtail: Pages translations can be created without page permissions when using simple_translation
CVE-2026-55468Medium· 4.3Wagtail: Improper restriction handling on Pages admin API
GHSA-92hv-j533-69wcLow· 3.7Wagtail: Identification of documents by SHA1 hash
GHSA-c2xx-cjmh-9q8fMedium· 5.3Wagtail: Improper restriction handling on descendant collections in Documents and Images API