CVE-2026-61663

Source
https://cve.org/CVERecord?id=CVE-2026-61663
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61663.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-61663
Aliases
Published
2026-08-20T18:07:28Z
Modified
2026-09-11T03:30:57Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
Details

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use PlaceholderRelationField. An active staff user without cms.use_structure or model-level view or change permission can request the //admin/cms/placeholder/object/<content_type_id>/structure/<object_id>/ endpoint with guessed content_type_id and object_id values. The response discloses placeholder slot names, plugin trees, plugin identifiers, labels, and object existence for frontend-editable objects. The fix applies user_can_view_placeholder_source to the non-PageContent branch while keeping the structure board read-only for view-only users. This issue is fixed in versions 5.0.9.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-639",
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61663.json"
}
References

Affected packages

Git / github.com/django-cms/django-cms

Affected ranges

Type
GIT
Repo
https://github.com/django-cms/django-cms
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.0.9"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.1.0
2.1.0.rc2
2.1.0.rc3
2.1.1
2.1.2
2.1.3
2.1.4
2.2
2.3
2.3.2
2.3.2.rc1
2.3.3
2.3.4
2.3.5
2.3rc1
2.4.0
2.4.0.rc1
2.4.1
3.*
3.0
3.0.0.beta
3.0.0.beta2
3.0.0.beta3
3.0.1
3.0.10
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0c1
3.0c2
3.1
3.2.0
3.2.0.rc1
3.2.0.rc10
3.2.0.rc11
3.2.0.rc12
3.2.0.rc13
3.2.0.rc14
3.2.0.rc3
3.2.0.rc4
3.2.0.rc5
3.2.0.rc6
3.2.0.rc7
3.2.0.rc8
3.2.0.rc9
3.3.0
3.3.0.rc2
3.3.0.rc3
3.3.0.rc4
3.4.0
3.4.0rc1
3.4.0rc2
3.4.0rc3
3.4.1
3.4.2
3.5.0
3.5.0rc1
3.5.1
3.5.2
4.*
4.0.0
4.0.0dev11
5.*
5.0.0
5.0.0a1
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8
Other
show
temporary

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61663.json"