CVE-2026-54262

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*
cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*
cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*

History

02 Jul 2026, 19:29

Type Values Removed Values Added
References () https://github.com/wagtail/wagtail/security/advisories/GHSA-8634-mr4j-r72c - () https://github.com/wagtail/wagtail/security/advisories/GHSA-8634-mr4j-r72c - Vendor Advisory
First Time Torchbox wagtail
Torchbox
CPE cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*

01 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-01 22:16

Updated : 2026-07-02 19:29


NVD link : CVE-2026-54262

Mitre link : CVE-2026-54262

CVE.ORG link : CVE-2026-54262


JSON object : View

Products Affected

torchbox

  • wagtail
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges