Skip to content
CVE-2026-54624: django CMS Structure Endpoint Vulnerability Disclosed

CVE-2026-54624: django CMS Structure Endpoint Vulnerability Disclosed

First seen 22 Aug 2026, 14:48 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 23, 2026 at 14:47 UTC
  • •CVE-2026-54624 allows unauthorized access to restricted page structures in django CMS.
  • •The vulnerability affects versions prior to 5.0.8 and has a CVSS score of 6.5.
  • •Users are urged to upgrade to version 5.0.8 to mitigate the risk of exploitation.

A vulnerability identified as CVE-2026-54624 affects django CMS versions prior to 5.0.8. The flaw allows any staff account to bypass page-view permissions, exposing restricted page structures. This occurs when the 'render_object_structure' function does not enforce user permissions, leading to potential data leakage of sensitive information such as link names and URLs. The vulnerability is rated with a CVSS score of 6.5, indicating a medium severity. It has been confirmed that the issue is fixed in version 5.0.8, released shortly after the vulnerability was disclosed. The flaw primarily impacts organizations using django CMS with specific permission settings enabled. Security updates are recommended for affected users to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 46d ago How this analysis works

Timeline

2026-08-20
CVE-2026-54624 published
The vulnerability was officially disclosed, detailing the bypass of page-view permissions in django CMS.
cvefeed.io
2026-08-20
CVSS score assigned
A CVSS base score of 6.5 was assigned to CVE-2026-54624, indicating medium severity.
Feedly
2026-08-20
Fix released in version 5.0.8
django CMS released version 5.0.8 to address the vulnerability, ensuring proper permission checks.
nvd.nist.gov

More articles in this cluster (4)

Following this threat?

Track CVE-2026-54624 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed