PT-2026-54838 · Wagtail · Wagtail
Harshakshit
·
Published
2026-07-01
·
Updated
2026-07-01
·
CVE-2026-54261
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wagtail versions prior to 7.0.8
Wagtail versions prior to 7.3.3
Wagtail versions prior to 7.4.2
Description
A missing permission check on the image preview endpoint allows a user with access to the Wagtail admin to preview any image. This issue does not expose the image object data and cannot be exploited by site visitors who lack admin access.
Recommendations
Update to version 7.0.8.
Update to version 7.3.3.
Update to version 7.4.2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wagtail