CVE-2026-44200General(torchbox / wagtail)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and potentially publish it. Permissions were correctly checked for the copy destination, but not for the source page. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-280

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wagtail

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-11)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
wagtail

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-08: 1Mentions · 2026-05-11: 3Technical Details · 2026-05-08: 1Technical Details · 2026-05-11: 305-0805-11
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-081
General1
2026-05-113
Disclosure2General1
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-44200 Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they do… https://www.cve.org/CVERecord?id=CVE-2026-44200 ----- Traducción: CVE-2026-44200 Wag… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑44200 in Wagtail, noting affected versions and a copy‑page flaw for limited‑access users, but offers no PoC, exploit, or patch details.

    0000034
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44200 Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they do… https://www.cve.org/CVERecord?id=CVE-2026-44200

    Post summary

    The post discloses CVE-2026-44200, a vulnerability in Wagtail versions prior to 7.0.7, 7.3.2, and 7.4 that allows users with limited page access to copy a page, indicating an information‑leak or privilege‑escalation issue.

    00000122
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44200 Unauthorized Page Access via Copy Function in Wagtail CMS Before 7.0.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44200

    Post summary

    The text merely announces the existence of CVE‑2026‑44200 with a brief description, without providing any PoC, exploit, patch, or evidence of active exploitation.

    0000036
    4.0K followersView on X
  • DailyCVE@dailycve
    General

    🟠 Wagtail, Improper Permission Handling, #CVE-2026-44200 (Moderate) https://dailycve.com/wagtail-improper-permission-handling-cve-2026-44200-moderate/

    Post summary

    The post announces CVE-2026-44200, labeling it a moderate severity improper permission handling flaw, but offers no further detail about exploitation, patches, or PoC.

    0000028
    198 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptorchboxwagtail---

Explore more