CVE-2026-44201
MEDIUMDescription
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections. This vulnerability is fixed in 7.0.7, 7.3.2, and 7.4.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| torchbox | wagtail |
| torchbox | wagtail |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-44201? +
How severe is CVE-2026-44201? +
What products are affected by CVE-2026-44201? +
How do I check if I'm vulnerable to CVE-2026-44201? +
Related Vulnerabilities
An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated …
Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to …
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.
Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to …