Junglewise Threat Intelligence

CVE-2024-32882: PYSEC-2026-2031 - Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`

CVE-2024-32882 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: wagtail (PyPI). Vendors: PyPI.

Executive brief

Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`

Affected products

  • PyPI wagtail

Related threats