CVE-2026-54262
4.3
MEDIUM
CVSS 3.1
EPSS 0.16%
Description
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.
How to fix CVE-2026-54262
To remediate CVE-2026-54262, upgrade the affected package to a fixed version below.
- —upgrade to 7.0.8 or later
Is CVE-2026-54262 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 7.0.8, >= 7.1, < 7.3.3, >= 7.4, < 7.4.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |