Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-44200

 

Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-44200

Published: May 5, 2026


Vulnerability identifier: #VU130200
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44200
CWE-ID: CWE-280
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper handling of insufficient permissions or privileges in page copy permission checks when copying pages. A remote user can copy a page they cannot access into an area of the site they do control to disclose sensitive information.

The copied page may then become viewable to the user, and it may also be possible to publish it.


Affected software

wagtail

How to mitigate CVE-2026-44200

Install security update from vendor's website.

wagtail - addressed in versions 7.0.7, 7.3.2

External References

Related Security Bulletins