<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:33:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-358840</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358840</link>
      <description>EUVD-2026-358840</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358840</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55468</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55468</link>
      <description>&lt;p&gt;Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access control, allowing a user with Wagtail admin access to retrieve restricted draft and live page content. This issue is fixed in versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55468</guid>
    </item>
    <item>
      <title>GHSA-3vrh-m9w7-v94f — Wagtail: Improper restriction handling on Pages admin API</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3vrh-m9w7-v94f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: wagtail&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields  without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`.&lt;/p&gt;
&lt;p&gt;The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Site owners unable to upgrade can apply the fix by overriding the relevant method on `PagesAdminAPIViewSet` to patch all vulnerable admin API endpoints:&lt;/p&gt;
&lt;p&gt;```python
# wagtail_hooks.py or AppConfig.ready()&lt;/p&gt;
&lt;p&gt;from wagtail.admin.api.views import PagesAdminAPIViewSet
from wagtail.permissions import page_permission_policy&lt;/p&gt;
&lt;p&gt;def _restricted_get_base_queryset(self):
    return page_permission_policy.explorable_instances(self.request.user)&lt;/p&gt;
&lt;p&gt;PagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset
```&lt;/p&gt;
&lt;p&gt;### Acknowledgements&lt;/p&gt;
&lt;p&gt;Many thanks to xuliang@QAX for reporting this issue.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;-   Visit Wagtail&amp;#39;s [support channels](https://docs.wagtail.org/en/stable/support.html)
-   Email us at [security@wagtail.org](mailto:security@wagtai…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: wagtail&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields  without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`.&lt;/p&gt;
&lt;p&gt;The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Site owners unable to upgrade can apply the fix by overriding the relevant method on `PagesAdminAPIViewSet` to patch all vulnerable admin API endpoints:&lt;/p&gt;
&lt;p&gt;```python
# wagtail_hooks.py or AppConfig.ready()&lt;/p&gt;
&lt;p&gt;from wagtail.admin.api.views import PagesAdminAPIViewSet
from wagtail.permissions import page_permission_policy&lt;/p&gt;
&lt;p&gt;def _restricted_get_base_queryset(self):
    return page_permission_policy.explorable_instances(self.request.user)&lt;/p&gt;
&lt;p&gt;PagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset
```&lt;/p&gt;
&lt;p&gt;### Acknowledgements&lt;/p&gt;
&lt;p&gt;Many thanks to xuliang@QAX for reporting this issue.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;-   Visit Wagtail&amp;#39;s [support channels](https://docs.wagtail.org/en/stable/support.html)
-   Email us at [security@wagtail.org](mailto:security@wagtai…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3vrh-m9w7-v94f</guid>
    </item>
    <item>
      <title>PYSEC-2026-3939 — Wagtail: Improper restriction handling on Pages admin API</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3939</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: wagtail&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields  without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`.&lt;/p&gt;
&lt;p&gt;The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Site owners unable to upgrade can apply the fix by overriding the relevant method on `PagesAdminAPIViewSet` to patch all vulnerable admin API endpoints:&lt;/p&gt;
&lt;p&gt;```python
# wagtail_hooks.py or AppConfig.ready()&lt;/p&gt;
&lt;p&gt;from wagtail.admin.api.views import PagesAdminAPIViewSet
from wagtail.permissions import page_permission_policy&lt;/p&gt;
&lt;p&gt;def _restricted_get_base_queryset(self):
    return page_permission_policy.explorable_instances(self.request.user)&lt;/p&gt;
&lt;p&gt;PagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset
```&lt;/p&gt;
&lt;p&gt;### Acknowledgements&lt;/p&gt;
&lt;p&gt;Many thanks to xuliang@QAX for reporting this issue.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;-   Visit Wagtail&amp;#39;s [support channels](https://docs.wagtail.org/en/stable/support.html)
-   Email us at [security@wagtail.org](mailto:security@wagtai…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: wagtail&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The internal Pages admin [API](https://docs.wagtail.org/en/stable/advanced_topics/api/index.html) incorrectly returns page fields  without access control when they are declared in `api_fields`. A user with access to the Wagtail admin can use this API to fetch draft and live page fields’ contents that are part of `api_fields` on the base page model (title, slug, seo_title, search_description), as well as all custom fields declared in `api_fields`.&lt;/p&gt;
&lt;p&gt;The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Site owners unable to upgrade can apply the fix by overriding the relevant method on `PagesAdminAPIViewSet` to patch all vulnerable admin API endpoints:&lt;/p&gt;
&lt;p&gt;```python
# wagtail_hooks.py or AppConfig.ready()&lt;/p&gt;
&lt;p&gt;from wagtail.admin.api.views import PagesAdminAPIViewSet
from wagtail.permissions import page_permission_policy&lt;/p&gt;
&lt;p&gt;def _restricted_get_base_queryset(self):
    return page_permission_policy.explorable_instances(self.request.user)&lt;/p&gt;
&lt;p&gt;PagesAdminAPIViewSet.get_base_queryset = _restricted_get_base_queryset
```&lt;/p&gt;
&lt;p&gt;### Acknowledgements&lt;/p&gt;
&lt;p&gt;Many thanks to xuliang@QAX for reporting this issue.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory:&lt;/p&gt;
&lt;p&gt;-   Visit Wagtail&amp;#39;s [support channels](https://docs.wagtail.org/en/stable/support.html)
-   Email us at [security@wagtail.org](mailto:security@wagtai…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3939</guid>
    </item>
  </channel>
</rss>
