CVE-2026-44197

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could access revisions of the page through the revision compare view if they knew the primary key of two revisions. This could potentially result in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*
cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*

History

12 May 2026, 15:58

Type Values Removed Values Added
CPE cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*
First Time Torchbox
Torchbox wagtail
References () https://github.com/wagtail/wagtail/security/advisories/GHSA-c6wj-9vcj-75pj - () https://github.com/wagtail/wagtail/security/advisories/GHSA-c6wj-9vcj-75pj - Vendor Advisory

11 May 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 16:17

Updated : 2026-05-12 15:58


NVD link : CVE-2026-44197

Mitre link : CVE-2026-44197

CVE.ORG link : CVE-2026-44197


JSON object : View

Products Affected

torchbox

  • wagtail
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges