CVE-2026-44200: Wagtail has improper permission handling when copying pages
A CMS user with limited access to pages could copy a page they don’t have access to to an area of the site they do. Once copied, they’d be able to view its contents, and potentially publish it. Permissions were correctly checked for the copy destination, but not for the source page.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-44200 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →