PYSEC-2026-3821

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/django-cms/PYSEC-2026-3821.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-3821
Aliases
Published
2026-09-10T09:44:52Z
Modified
2026-09-10T12:15:03Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
Details

Impact

The only authorization gate on the duplicate flow is PageAdmin.has_add_permission, which checks user_can_add_page(user, site) / user_can_add_subpage(...) — i.e. “may this user create a page at all”. Nothing checks the user’s relationship to the page being copied:

  • cms/admin/forms.pyDuplicatePageForm.source = ModelChoiceField(queryset=Page.objects.all(), widget=HiddenInput()) spans every page in the database, on every site.
  • cms/admin/forms.pyAddPageForm.__init__ returns early when the source widget is hidden, so the queryset is never narrowed to the user’s site/subtree.
  • cms/admin/forms.pyAddPageForm.clean() validates only URL uniqueness; source is never validated against the user.
  • cms/admin/pageadmin.pyduplicate() seeds source from the URL only on GET; on POST the value comes entirely from the request body.
  • cms/admin/forms.pyAddPageForm.save()from_source() performs source.copy(..., permissions=False) and copies every placeholder and all plugins of source into a new page on the attacker’s site. Because permissions=False drops the source’s view restrictions, the resulting copy is fully readable by the attacker.

This crosses a real privilege boundary: a staff user restricted (via CMS_PERMISSION) to their own site or subtree can exfiltrate the content of restricted pages and of pages belonging to other tenants.

Read-back is trivial (verified): the copy is created on the attacker’s site and, because copy(..., permissions=False) strips the source’s view restrictions, the new page is unrestricted. user_can_view_page() then returns True for it (unrestricted + PUBLIC_FOR), so the attacker — or even an anonymous visitor — can read the duplicated content directly from the front end. No further permission on the new page is required.

Proof of concept

  1. Log in as a staff user attacker who has add page permission but no view/change permission on a target (secret / other-site) page SECRET_ID.
  2. Send (the URL <id> only needs to be a PageContent the attacker can already see — e.g. one of their own pages; the victim id goes in the POST body):
POST /admin/cms/pagecontent/<MY_OWN_PAGECONTENT_ID>/duplicate/ HTTP/1.1
Cookie: sessionid=<attacker session>
Content-Type: application/x-www-form-urlencoded

csrfmiddlewaretoken=...&title=x&slug=x&language=en&source=<SECRET_ID>
  1. A new, unrestricted page is created under the attacker’s site containing a verbatim copy of the secret page’s plugins, which the attacker can now preview/edit/read.

Patches

Enforce an object-level permission check on source:

class DuplicatePageForm(AddPageForm):
    source = forms.ModelChoiceField(
        queryset=Page.objects.all(),
        required=True,
        widget=forms.HiddenInput(),
    )

    def clean_source(self):
        source = self.cleaned_data.get("source")
        if source and not user_can_view_page(self._user, source):
            raise ValidationError(_("You do not have permission to copy this page."))
        return source

(user_can_view_page is imported from cms.utils.page_permissions.)

Workarounds

Until patched, restrict access to the cms.add_page permission to fully-trusted staff, or disable the duplicate action for delegated/limited editors.

References

  • cms/admin/pageadmin.pyduplicate(), has_add_permission(), get_urls()
  • cms/admin/forms.pyDuplicatePageForm, AddPageForm.__init__/clean/save/from_source
  • Regression tests: cms/tests/test_forms.py::DuplicatePageFormSecurityTestCase
References

Affected packages

PyPI / django-cms

Package

Name
django-cms
View open source insights on deps.dev
Purl
pkg:pypi/django-cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.0.9

Affected versions

2.*
2.0.1
2.0.2
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2
2.2.1
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.4.0
2.4.1
2.4.2
2.4.3
3.*
3.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.1.0.b1
3.1.0rc1
3.1.0rc2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0rc2
3.3.0rc3
3.3.0rc4
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.5.0
3.5.1
3.5.2
3.5.3
3.5.4
3.6.0rc1
3.6.0rc3
3.6.0
3.6.1
3.7.0rc1
3.7.0rc2
3.7.0
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0rc1
3.8.0
3.8.1
3.8.2
3.9.0rc1
3.9.0rc2
3.9.0rc3
3.9.0
3.10.0rc1
3.10.0rc2
3.10.0
3.10.1rc1
3.10.1
3.11.0
3.11.1rc1
3.11.1
3.11.2
3.11.3
3.11.4
3.11.5
3.11.6
3.11.7
3.11.8
3.11.9
3.11.10
3.11.11
4.*
4.1.0rc1
4.1.0rc2
4.1.0rc3
4.1.0rc4
4.1.0rc5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.9
4.1.10
4.1.11
5.*
5.0.0a1
5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/django-cms/PYSEC-2026-3821.yaml"