{"id":"GHSA-jm5p-837g-rv8g","aliases":[],"url":"https://o3.security/vulnerability/GHSA-jm5p-837g-rv8g","summary":"Wagtail: Improper restriction handling on Page translation API endpoint","details":"### Impact\nA CMS user with the \"submit translations\" permission, could use the Admin API's \"copy for translation\" endpoint to copy an existing page that they do not have edit access to, allowing them to view its contents.\n\n### Patches\nPatched versions have been released as Wagtail 7.0.9, 7.3.4, 7.4.3 and 8.0rc2.\n\n### Workarounds\nN/A\n\n### Acknowledgements\nMany thanks to tinyb0y for reporting this issue.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n* Visit Wagtail's [support channels](https://docs.wagtail.org/en/stable/support.html)\n* Email us at [security@wagtail.org](mailto:security@wagtail.org) (view our [security policy](https://github.com/wagtail/wagtail/security/policy) for more information).","published":"2026-08-20T18:45:27Z","modified":"2026-08-20T19:00:07.496785371Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"wagtail","fixedVersion":"7.0.9"},{"ecosystem":"PyPI","name":"wagtail","fixedVersion":"7.3.4"},{"ecosystem":"PyPI","name":"wagtail","fixedVersion":"7.4.3"},{"ecosystem":"PyPI","name":"wagtail","fixedVersion":"8.0rc2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/wagtail/wagtail/security/advisories/GHSA-jm5p-837g-rv8g"},{"type":"PACKAGE","url":"https://github.com/wagtail/wagtail"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T19:00:07.496785371Z"}}