Executive brief
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
Affected products
- PyPI wagtail
Junglewise Threat Intelligence
CVE-2024-32882 · Severity: low · CVSS 3.1 · Published 2026-07-07
Technologies: wagtail (PyPI). Vendors: PyPI.
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`