Missing Authorization in wagtail - CVE-2026-25517

 

Missing Authorization in wagtail - CVE-2026-25517

Published: May 5, 2026


Vulnerability identifier: #VU130195
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-25517
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in admin preview endpoints when handling crafted preview form submissions. A remote privileged user can submit a specially crafted form to obtain a preview rendering of page, snippet, or site setting objects and disclose sensitive information.

The issue is limited to users with access to the Wagtail admin, and the existing data of the targeted object itself is not exposed.


Affected software

wagtail

How to mitigate CVE-2026-25517

Install security update from vendor's website.

wagtail - addressed in versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, 7.3

External References

Related Security Bulletins