Junglewise Threat Intelligence

CVE-2026-34086: Wikimedia Foundation AbuseFilter vulnerability

CVE-2026-34086 · Severity: info · CVSS 2.1 · Published 2026-05-11

Vendors: Wikimedia Foundation.

Executive brief

A vulnerability exists in the Wikimedia Foundation's AbuseFilter, a tool used to detect and prevent malicious edits on wiki platforms. While specific details of the flaw are limited, it could potentially allow authenticated users to bypass certain security filters or cause minor disruptions to content moderation. The impact is considered low, but organizations using this extension should update to the latest versions to maintain the integrity of their automated moderation systems.

Technical details

A vulnerability of unspecified class exists in the Wikimedia Foundation AbuseFilter extension. According to the CVSS 4.0 vector provided by the vendor, the issue is network-exploitable but requires high attack complexity, specific conditions (Attack Terminology: Provable), and low-privileged user authentication. It also requires user interaction. Successful exploitation results in low impact to confidentiality and integrity, with no impact on availability. The issue has been addressed in versions 1.43.7, 1.44.4, and 1.45.2.

Affected products

  • Wikimedia Foundation AbuseFilter before 1.43.7, 1.44.4, 1.45.2

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory

References

Related threats