CVE-2026-54259Medium· 4.3▾ SunlitWagtail: Improper restriction handling on Documents and Images chosen endpoints
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 20.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.3%
The Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and name and URLs of documents and images in those collections.
The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin.
Patched versions have been released as Wagtail 7.0.8, 7.3.3, 7.4.2.
N/A
Many thanks to @harshakshit for reporting this issue.
If you have any questions or comments about this advisory:
wagtail < 7.0.8wagtail >= 7.1, < 7.3.3wagtail >= 7.4, < 7.4.2Upgrade to a patched release:
wagtail 7.0.8wagtail 7.3.3wagtail 7.4.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54261Medium· 6.5Wagtail: Improper permission handling in image preview
CVE-2026-54262Medium· 4.3Wagtail: Pages translations can be created without page permissions when using simple_translation
CVE-2026-55468Medium· 4.3Wagtail: Improper restriction handling on Pages admin API
GHSA-92hv-j533-69wcLow· 3.7Wagtail: Identification of documents by SHA1 hash
GHSA-c2xx-cjmh-9q8fMedium· 5.3Wagtail: Improper restriction handling on descendant collections in Documents and Images API
GHSA-x5cx-w6p2-mxf2Medium· 6.5Wagtail: Improper permission handling when copying snippets