Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-54262

 

Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-54262

Published: June 16, 2026


Vulnerability identifier: #VU134576
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54262
CWE-ID: CWE-280
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper handling of insufficient permissions or privileges in the simple_translation page translation feature when creating page translations. A remote user can create translations for pages they do not have permission to access to disclose sensitive information.

Exploitation requires the "Can submit translation" permission.


Affected software

wagtail

How to mitigate CVE-2026-54262

Install security update from vendor's website.

wagtail - addressed in versions 7.0.8, 7.3.3, 7.4.2

External References

Related Security Bulletins