Executive brief
MediaWiki, the software powering Wikipedia and many other wikis, contains a vulnerability that could allow unauthorized individuals to access sensitive information. This could lead to the exposure of private data or internal system details that should not be publicly visible. Organizations using MediaWiki should update to the latest patched versions to protect their data and maintain user privacy.
Technical details
A sensitive information disclosure vulnerability (CWE-200) exists in Wikimedia Foundation MediaWiki. The flaw allows an unauthorized actor to access data that is intended to be restricted. The vulnerability is reachable over the network and requires some level of user interaction (UI:P) according to the CVSS 4.0 vector. It affects multiple branches of the software, and fixes have been released in versions 1.43.7, 1.44.4, and 1.45.2. Attackers can leverage this to gain insights into the system or user data without proper authorization.
Affected products
- Wikimedia Foundation MediaWiki before 1.43.7, 1.44.4, 1.45.2
Timeline
- 2026-05-11: disclosed: Initial publication of the CVE record.