{"apiVersion":"1.0","identifier":"CVE-2026-54622","description":"django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the destination clipboard. The _copy_plugin_to_clipboard and _copy_placeholder_to_clipboard paths accept source_placeholder_id and source_plugin_id values but use has_copy_plugins_permission and check_source only for the requesting user-s clipboard, without validating the source placeholder. Under CMS_PERMISSION, a staff user with the global add permission for a plugin type can copy plugins from an unauthorized page or placeholder into the user-s clipboard and read secret text, link names, and URLs. This issue is fixed in versions 5.0.8.","publishedAt":"2026-08-20T19:16:55","lastModifiedAt":"2026-08-20T19:16:55","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54622","cvssScore":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00239,"riskScore":0.66,"affectedProduct":"django CMS","affectedVersions":"<5.0.8","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-54622","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-54622","en":"https://www.redsauce.net/en/cves/CVE-2026-54622","fr":"https://www.redsauce.net/fr/cves/CVE-2026-54622","pt":"https://www.redsauce.net/pt/cves/CVE-2026-54622","de":"https://www.redsauce.net/de/cves/CVE-2026-54622","sk":"https://www.redsauce.net/sk/cves/CVE-2026-54622","el":"https://www.redsauce.net/el/cves/CVE-2026-54622"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-54622"}}