Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-54262
Published: June 16, 2026
wagtail
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper handling of insufficient permissions or privileges in the simple_translation page translation feature when creating page translations. A remote user can create translations for pages they do not have permission to access to disclose sensitive information.
Exploitation requires the "Can submit translation" permission.