Junglewise Threat Intelligence

CVE-2026-34087: Wikimedia Foundation OATHAuth sensitive information exposure

CVE-2026-34087 · Severity: high · CVSS 7.5 · Published 2026-05-11

Vendors: Wikimedia Foundation.

Executive brief

A security vulnerability has been identified in the OATHAuth extension used by Wikimedia and other MediaWiki installations to provide two-factor authentication. This flaw could allow an unauthorized individual to access sensitive information that should be protected. If exploited, this could compromise the privacy of user accounts or reveal internal configuration details, potentially aiding further attacks.

Technical details

A sensitive information disclosure vulnerability (CWE-200) exists in the Wikimedia Foundation OATHAuth extension. The flaw allows an authenticated attacker with low privileges to access information they are not authorized to view, provided there is some level of user interaction. The vulnerability is present in versions prior to 1.43.7, 1.44.4, and 1.45.2. While the specific nature of the exposed data is not detailed in the advisory, it typically involves cryptographic secrets or user-specific authentication metadata within the OATH framework. Patches have been released to address this issue in the affected branches.

Affected products

  • Wikimedia Foundation OATHAuth Before 1.43.7, 1.44.4, 1.45.2

Timeline

  • 2026-05-11: advisory: NVD publication date
  • 2026-05-11: disclosed: Initial disclosure by Wikimedia Foundation

References