{"id":"PYSEC-2026-3939","summary":"Wagtail: Improper restriction handling on Pages admin API","details":"### Impact\n\nThe internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields  without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`.\n\nThe vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.\n\n### Patches\n\nPatched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.\n\n### Workarounds\n\nSite owners unable to upgrade can apply the fix by overriding the relevant method on `PagesAdminAPIViewSet` to patch all vulnerable admin API endpoints:\n\n```python\n# wagtail_hooks.py or AppConfig.ready()\n\nfrom wagtail.admin.api.views import PagesAdminAPIViewSet\nfrom wagtail.permissions import page_permission_policy\n\n\ndef _restricted_get_base_queryset(self):\n    return page_permission_policy.explorable_instances(self.request.user)\n\nPagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset\n```\n\n### Acknowledgements\n\nMany thanks to xuliang@QAX for reporting this issue.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n-   Visit Wagtail's [support channels](https://docs.wagtail.org/en/stable/support.html)\n-   Email us at [security@wagtail.org](mailto:security@wagtail.org) (view our [security policy](https://github.com/wagtail/wagtail/security/policy) for more information).","aliases":["CVE-2026-55468","GHSA-3vrh-m9w7-v94f"],"modified":"2026-09-10T12:15:14.701664068Z","published":"2026-09-10T09:44:52.570171Z","references":[{"type":"WEB","url":"https://github.com/wagtail/wagtail/security/advisories/GHSA-3vrh-m9w7-v94f"},{"type":"PACKAGE","url":"https://github.com/wagtail/wagtail"},{"type":"PACKAGE","url":"https://pypi.org/project/wagtail"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3vrh-m9w7-v94f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55468"}],"affected":[{"package":{"name":"wagtail","ecosystem":"PyPI","purl":"pkg:pypi/wagtail"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.9"},{"introduced":"7.1"},{"fixed":"7.3.4"},{"introduced":"7.4"},{"fixed":"7.4.3"},{"introduced":"8.0rc1"},{"fixed":"8.0rc2"}]}],"versions":["0.1","0.2","0.3","0.3.1","0.4","0.4.1","0.5","0.6","0.7","0.8","0.8.1","0.8.10","0.8.2","0.8.3","0.8.4","0.8.5","0.8.6","0.8.7","0.8.8","0.8.9","1.0","1.0b1","1.0b2","1.0rc1","1.0rc2","1.1","1.10","1.10.1","1.10rc1","1.11","1.11.1","1.11rc1","1.12","1.12.1","1.12.2","1.12.3","1.12.4","1.12.5","1.12.6","1.12rc1","1.13","1.13.1","1.13.2","1.13.3","1.13.4","1.13rc1","1.1rc1","1.2","1.2rc1","1.3","1.3.1","1.3rc1","1.4","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4rc1","1.5","1.5.1","1.5.2","1.5.3","1.5rc1","1.6","1.6.1","1.6.2","1.6.3","1.6rc1","1.7","1.7rc1","1.8","1.8.1","1.8.2","1.8rc1","1.9","1.9.1","1.9rc1","2.0","2.0.1","2.0.2","2.0b1","2.0rc1","2.1","2.1.1","2.1.2","2.1.3","2.10","2.10.1","2.10.2","2.10rc1","2.10rc2","2.11","2.11.1","2.11.2","2.11.3","2.11.4","2.11.5","2.11.6","2.11.7","2.11.8","2.11.9","2.11rc1","2.12","2.12.1","2.12.2","2.12.3","2.12.4","2.12.5","2.12.6","2.12rc1","2.13","2.13.1","2.13.2","2.13.3","2.13.4","2.13.5","2.13rc1","2.13rc2","2.13rc3","2.14","2.14.1","2.14.2","2.14rc1","2.15","2.15.1","2.15.2","2.15.3","2.15.4","2.15.5","2.15.6","2.15rc1","2.15rc2","2.16","2.16.1","2.16.2","2.16.3","2.16rc1","2.16rc2","2.1rc1","2.1rc2","2.2","2.2.1","2.2.2","2.2rc1","2.2rc2","2.3","2.3rc1","2.3rc2","2.4","2.4rc1","2.5","2.5.1","2.5.2","2.5rc1","2.6","2.6.1","2.6.2","2.6.3","2.6rc1","2.7","2.7.1","2.7.2","2.7.3","2.7.4","2.7rc1","2.7rc2","2.8","2.8.1","2.8.2","2.8rc1","2.9","2.9.1","2.9.2","2.9.3","2.9rc1","3.0","3.0.1","3.0.2","3.0.3","3.0rc1","3.0rc2","3.0rc3","4.0","4.0.1","4.0.2","4.0.3","4.0.4","4.0rc1","4.0rc2","4.1","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.1.6","4.1.7","4.1.8","4.1.9","4.1rc1","4.2","4.2.1","4.2.2","4.2.3","4.2.4","4.2rc1","5.0","5.0.1","5.0.2","5.0.3","5.0.4","5.0.5","5.0rc1","5.1","5.1.1","5.1.2","5.1.3","5.1rc1","5.2","5.2.1","5.2.2","5.2.3","5.2.4","5.2.5","5.2.6","5.2.7","5.2.8","5.2rc1","6.0","6.0.1","6.0.2","6.0.3","6.0.4","6.0.5","6.0.6","6.0rc1","6.1","6.1.1","6.1.2","6.1.3","6.1rc1","6.1rc2","6.2","6.2.1","6.2.2","6.2.3","6.2.4","6.2rc1","6.3","6.3.1","6.3.2","6.3.3","6.3.4","6.3.5","6.3.6","6.3.7","6.3.8","6.3rc1","6.3rc2","6.4","6.4.1","6.4.2","6.4rc1","7.0","7.0.1","7.0.2","7.0.3","7.0.4","7.0.5","7.0.6","7.0.7","7.0.8","7.0rc1","7.1","7.1.1","7.1.2","7.1.3","7.2","7.2.1","7.2.2","7.2.3","7.2rc1","7.3","7.3.1","7.3.2","7.3.3","7.3rc1","7.4","7.4.1","7.4.2","8.0rc1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/wagtail/PYSEC-2026-3939.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}