CVE 4.3 MEDIUM

Wagtail: Improper permission handling when viewing page history_CVE-2026-44198

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without the ability to edit a page could still access the history report for the page, potentially resulting in disclosure of sensitive information. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.

Basic Information

ID CVE-2026-44198
Source GitHub_M
Published May 11, 2026 at 14:40

Affected Product

Vendor wagtail
Product wagtail
Version < 7.0.7
Affected Versions wagtail wagtail < 7.0.7
wagtail wagtail >= 7.1, < 7.3.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.