Access Control Flaw in Wagtail CMS by Wagtail
CVE-2026-44200

6.5MEDIUM

Key Information:

Vendor

Wagtail

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-44200?

Wagtail, an open-source content management system utilizing Django, contains a vulnerability that allows limited access users to copy pages they do not have permission to view. Although the destination for the copy is properly checked, the source page’s permissions are not enforced. This flaw enables unauthorized content access and potential publication by users to whom it should not be available. The issue was resolved in versions 7.0.7, 7.3.2, and 7.4.

Affected Version(s)

wagtail < 7.0.7 < 7.0.7

wagtail >= 7.1, < 7.3.2 < 7.1, 7.3.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.