CVE-2026-54624

Source
https://cve.org/CVERecord?id=CVE-2026-54624
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54624.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54624
Aliases
Published
2026-08-20T18:04:38Z
Modified
2026-09-11T03:30:18Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
django CMS: Structure endpoint bypasses page-view permission
Details

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent object without calling user_can_view_page(). Any staff account can request a restricted page’s structure when CMS_PERMISSION is enabled and the page has view restrictions or CMS_PUBLIC_FOR is set to staff. The response exposes plugin get_short_description() values, including link names, URLs, and text snippets, rather than only the page shape. This issue is fixed in versions 5.0.8.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-285",
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54624.json"
}
References

Affected packages

Git / github.com/django-cms/django-cms

Affected ranges

Type
GIT
Repo
https://github.com/django-cms/django-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.0.8"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.1.0
2.1.0.rc2
2.1.0.rc3
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.3
2.3.2
2.3.2.rc1
2.3.3
2.3.4
2.3.5
2.3rc1
2.4.0
2.4.0.rc1
2.4.1
3.*
3.0
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.1
3.0.10
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0c1
3.0c2
3.1
3.2.0
3.2.0.rc1
3.2.0.rc10
3.2.0.rc11
3.2.0.rc12
3.2.0.rc13
3.2.0.rc14
3.2.0.rc3
3.2.0.rc4
3.2.0.rc5
3.2.0.rc6
3.2.0.rc7
3.2.0.rc8
3.2.0.rc9
3.3.0
3.3.0.rc2
3.3.0.rc3
3.3.0.rc4
3.4.0
3.4.0rc1
3.4.0rc2
3.4.0rc3
3.4.1
3.4.2
3.5.0
3.5.0rc1
3.5.1
3.5.2
4.*
4.0.0
4.0.0dev11
5.*
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
Other
show
temporary

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54624.json"