Access Control Flaw in Wagtail CMS by Wagtail
CVE-2026-44200
6.5MEDIUM
What is CVE-2026-44200?
Wagtail, an open-source content management system utilizing Django, contains a vulnerability that allows limited access users to copy pages they do not have permission to view. Although the destination for the copy is properly checked, the source page’s permissions are not enforced. This flaw enables unauthorized content access and potential publication by users to whom it should not be available. The issue was resolved in versions 7.0.7, 7.3.2, and 7.4.
Affected Version(s)
wagtail < 7.0.7 < 7.0.7
wagtail >= 7.1, < 7.3.2 < 7.1, 7.3.2
