Impact
Wagtail versions earlier than 7.0.8, 7.3.3, and 7.4.2 expose file names, URLs, and basic metadata for documents and images that an administrator does not have permission to choose. The flaw is an improper authorization check (CWE‑280) that leaks asset information but does not allow code execution, privilege escalation, or denial of service.
Affected Systems
Systems running Wagtail CMS before the listed patch versions—7.0.8, 7.3.3, or 7.4.2—are affected. Administrators accessing the Wagtail administrative interface who are not granted the "choose" permission can see the restricted media items.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of <1% shows a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated admin login, so external attackers without admin privileges cannot exploit the flaw. The overall risk for external actors remains low, while internal privileged users could obtain additional sensitive information.
OpenCVE Enrichment