PYSEC-2026-3826

    Dashboard / Vulnerabilities / PYSEC-2026-3826

    PYSEC-2026-3826

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: django CMS: Structure endpoint bypasses page-view permission

    Details: ### Summary The structure-board endpoint (`render_object_structure`) renders a page's plugin structure without verifying that the requesting user is allowed to view the page. The edit and preview endpoints enforce this via `render_page()`, but the structure endpoint does not, allowing a low-privileged staff user to read the plugin structure of a view-restricted page. ### Details `render_object_structure` (in `cms/views.py`) loads the `PageContent` object and renders `cms/toolbar/structure.html` directly. Unlike `render_object_endpoint` (used by edit/preview), which renders through `render_pagecontent` → `render_page` and calls `user_can_view_page(request.user, page)` (returning 404 when the user may not view the page), the structure endpoint performs no page-level authorization. The rendered structure board includes each plugin's `get_short_description()` (e.g. link names/URLs, text snippets), so the content of a restricted page is disclosed, not just its shape. ### Impact A staff user (any account with `is_staff=True`) who lacks view permission on a view-restricted page can retrieve that page's plugin structure and short descriptions by requesting the structure endpoint with the page's content-type id and object id. This only applies when `CMS_PERMISSION=True` and the page has view restrictions (or `CMS_PUBLIC_FOR='staff'`). Sites without per-page view restrictions are not affected. ### Patches Fixed in 5.0.8: the structure endpoint now enforces `user_can_view_page()` for `PageContent` objects, matching edit/preview. ### Workarounds None other than restricting staff access. Upgrade is recommended. ### Credits Reported by the security team at the University of Sydney ([@reporter]).

    Affected packages

    Package

    Name: django-cms

    Purl: pkg:pypi/django-cms

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.0.8

    Affected versions

    2.0.1
    2.0.2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-3826 | CVE-DB