Executive brief
Wagtail is a popular Django-based content management system. Due to a missing permission check in the image preview feature, admin users can view preview versions of any image in the system, potentially seeing content they shouldn't have access to. While the image file metadata itself isn't exposed, this represents an unauthorized information disclosure that could compromise content confidentiality. The vulnerability requires existing admin panel access, so it primarily affects organizations with multiple content editors at different permission levels.
Technical details
This is an improper access control vulnerability (CWE-280) in Wagtail's image preview endpoint. The image preview view fails to validate whether the requesting user has permission to access the specific image before serving the preview. An authenticated user with access to the Wagtail admin panel can directly request image previews for any image by ID and filter specification, bypassing per-instance permission policies. The attack vector is network-based and requires low privileges (Wagtail admin user), with no user interaction needed. The impact is limited to image content disclosure (high confidentiality impact) with no integrity or availability impact. Patches are available in Wagtail 7.0.8, 7.3.3, and 7.4.2; workarounds involve adding an explicit permission check wrapper to the preview URL pattern.
Affected products
- Wagtail Wagtail < 7.0.8, >= 7.1 and < 7.3.3, >= 7.4 and < 7.4.2
Timeline
- 2026-06-15: disclosed
- 2026-06-15: patched: Patches released for versions 7.0.8, 7.3.3, and 7.4.2
- 2026-08-20: advisory