Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-44199

 

Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-44199

Published: May 5, 2026


Vulnerability identifier: #VU130198
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44199
CWE-ID: CWE-280
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete form submissions on unauthorized form pages.

The vulnerability exists due to improper handling of insufficient permissions or privileges in form submission deletion handling when processing crafted deletion requests through the Wagtail admin. A remote user can craft a form submission to delete submissions for form pages they do not have access to in order to delete form submissions on unauthorized form pages.

The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.


Affected software

wagtail

How to mitigate CVE-2026-44199

Install security update from vendor's website.

wagtail - addressed in versions 7.0.7, 7.3.2

External References

Related Security Bulletins