Impact
An improper permission check in the image preview endpoint lets any user with Wagtail admin access view any image stored in the system, bypassing the intended image‑level restrictions. The vulnerability does not expose the underlying image data such as metadata; it simply allows the admin to render the image for preview. Because only users with administrative credentials can reach the endpoint, an ordinary site visitor cannot exploit this flaw. The flaw is a CWE‑280 permission bypass.
Affected Systems
All Wagtail installations older than the patched releases 7.0.8, 7.3.3, and 7.4. the Wagtail admin interface can exploit the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild, and the issue is not listed in CISA’s KEV catalog. Exploitation requires administrative access, so the attack vector is most likely internal or targeted. A malicious or compromised admin can use the endpoint to preview any image, potentially revealing sensitive visual content beyond their authorized scope.
OpenCVE Enrichment