Access Control Flaw in Wagtail CMS by Django
CVE-2026-44199
6.5MEDIUM
What is CVE-2026-44199?
Wagtail, an open source content management system based on Django, has a vulnerability that allows a CMS user with limited access to form pages to delete submissions from inaccessible forms. This occurs when the user constructs a specific form submission that targets submissions on a form page they can access. However, this vulnerability requires the user to have administrative access and cannot be exploited by typical site visitors. The issue has been rectified in Wagtail CMS versions 7.0.7, 7.3.2, and 7.4.
Affected Version(s)
wagtail < 7.0.7 < 7.0.7
wagtail >= 7.1, < 7.3.2 < 7.1, 7.3.2
