Junglewise Threat Intelligence

CVE-2026-44201: Wagtail information disclosure in Documents and Images API

CVE-2026-44201 · Severity: medium · CVSS 5.3 · Published 2026-05-11

Technologies: wagtail (PyPI), Wagtail. Vendors: PyPI, Wagtail.

Executive brief

Wagtail, a popular content management system, has a vulnerability in its Documents and Images API. This flaw allows unauthorized users to view the names and filenames of files stored in private collections that should otherwise be restricted. While the actual content of the files may not be directly exposed through this specific bug, the leak of metadata can reveal sensitive organizational information or internal project details.

Technical details

A vulnerability exists in Wagtail's Documents and Images API due to improper handling of insufficient permissions (CWE-280). The API incorrectly lists items belonging to private collections, exposing metadata such as filenames and document names to any user with API access. This is exploitable over the network without authentication if the API is configured without mandatory auth. The issue affects Wagtail versions prior to 7.0.7 and versions between 7.1 and 7.3.2. Patches are available in versions 7.0.7, 7.3.2, and 7.4 LTS. A temporary workaround is to enforce authentication on the affected API endpoints.

Affected products

  • Wagtail Wagtail < 7.0.7, >= 7.1, < 7.3.2

Timeline

  • 2026-05-08: advisory: GitHub Advisory published
  • 2026-05-08: patched: Wagtail 7.0.7 and 7.3.2 released

References

Related threats