Access Control Flaw in Wagtail CMS by Django
CVE-2026-44199

6.5MEDIUM

Key Information:

Vendor

Wagtail

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-44199?

Wagtail, an open source content management system based on Django, has a vulnerability that allows a CMS user with limited access to form pages to delete submissions from inaccessible forms. This occurs when the user constructs a specific form submission that targets submissions on a form page they can access. However, this vulnerability requires the user to have administrative access and cannot be exploited by typical site visitors. The issue has been rectified in Wagtail CMS versions 7.0.7, 7.3.2, and 7.4.

Affected Version(s)

wagtail < 7.0.7 < 7.0.7

wagtail >= 7.1, < 7.3.2 < 7.1, 7.3.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.