Junglewise Threat Intelligence

CVE-2026-13707: Wikimedia Foundation OAuth session fixation in MWOAuthServer

CVE-2026-13707 · Severity: info · CVSS 0 · Published 2026-07-01

Vendors: Wikimedia Foundation.

Executive brief

A security flaw exists in the Wikimedia Foundation OAuth extension, which is used to manage third-party application access to Wikimedia sites. This vulnerability could allow an attacker to fixate a user's session, potentially leading to unauthorized access to a user's account or data if the user is tricked into using a pre-defined session. While the reported severity is low, it represents a risk to the integrity of user authentication sessions.

Technical details

A session fixation vulnerability (CWE-384) exists in the Wikimedia Foundation OAuth extension, specifically within the 'src/Backend/MWOAuthServer.php' component. The flaw allows a remote attacker to potentially fixate a session identifier, which can be exploited if a victim authenticates using a session ID known to the attacker. The attack requires network access and some level of user interaction. The vulnerability affects multiple version branches including 1.46.0, 1.45.4, 1.44.6, and 1.43.9. Although the CNA has assigned a CVSS score of 0.0, session fixation typically allows for session hijacking under specific conditions.

Affected products

  • Wikimedia Foundation OAuth extension <= 1.46.0, 1.45.4, 1.44.6, 1.43.9

Timeline

  • 2026-07-01: advisory: CVE-2026-13707 published by Wikimedia Foundation

References