CVE-2026-44200

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and potentially publish it. Permissions were correctly checked for the copy destination, but not for the source page. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*
cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*

History

12 May 2026, 15:57

Type Values Removed Values Added
CPE cpe:2.3:a:torchbox:wagtail:*:*:*:*:*:*:*:*
First Time Torchbox
Torchbox wagtail
References () https://github.com/wagtail/wagtail/security/advisories/GHSA-67rv-mg8q-5pf3 - () https://github.com/wagtail/wagtail/security/advisories/GHSA-67rv-mg8q-5pf3 - Vendor Advisory

11 May 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 16:17

Updated : 2026-05-12 15:57


NVD link : CVE-2026-44200

Mitre link : CVE-2026-44200

CVE.ORG link : CVE-2026-44200


JSON object : View

Products Affected

torchbox

  • wagtail
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges