mediumCVSS 6.5Vulnerability

GHSA-jm5p-837g-rv8g

### Impact A CMS user with the "submit translations" permission, could use the Admin API's "copy for translation" endpoint to copy an existing page that they do not have edit access to, allowing them to view its contents. ### Patches Patched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2. ### Workarounds N/A ### Acknowledgements Many thanks to tinyb0y for reporting this issue. ### For more information If you have any questions or comments about this advisory: * Visit Wagtail's [support channels](https://docs.wagtail.org/en/stable/support.html) * Email us at [[email protected]](mailto:[email protected]) (view our [security policy](https://github.com/wagtail/wagtail/security/policy) for more information).

Properties

ghsa_id
GHSA-jm5p-837g-rv8g
severity
medium
summary
Wagtail: Improper restriction handling on Page translation API endpoint
cvss_score
6.5
cve_id
GHSA-jm5p-837g-rv8g
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-08-20T18:45:27Z
source_url
https://github.com/advisories/GHSA-jm5p-837g-rv8g
ghsa_updated
2026-08-20T18:45:30Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/wagtail

AFFECTS (1)

[Software]pip/wagtail

HAS_WEAKNESS (1)

[Weakness]Improper Handling of Insufficient Permissions or Privileges

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-jm5p-837g-rv8g (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal