Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-54261

 

Improper Handling of Insufficient Permissions or Privileges in wagtail - CVE-2026-54261

Published: June 16, 2026


Vulnerability identifier: #VU134575
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54261
CWE-ID: CWE-280
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper handling of insufficient permissions or privileges in the image preview endpoint when handling image preview requests. A remote user can request a preview of any image to disclose sensitive information.

The issue is limited to users with access to the Wagtail admin, and the existing data of the image object itself is not exposed.


Affected software

wagtail

How to mitigate CVE-2026-54261

Install security update from vendor's website.

wagtail - addressed in versions 7.0.8, 7.3.3, 7.4.2

External References

Related Security Bulletins