Junglewise Threat Intelligence

CVE-2026-34090: Wikimedia Foundation CheckUser information exposure in Suggested Investigations

CVE-2026-34090 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Wikimedia Foundation CheckUser. Vendors: Wikimedia Foundation.

Executive brief

A vulnerability in the CheckUser extension for MediaWiki could allow unauthorized users to view suppressed or hidden usernames. CheckUser is a tool used by wiki administrators to investigate disruptive behavior and maintain site integrity. If exploited, this flaw could lead to the exposure of sensitive identity information that was intended to be restricted from public or low-level administrative view.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Wikimedia Foundation CheckUser extension within the Special:SuggestedInvestigations component. The application fails to properly filter or redact suppressed usernames, making them visible to users who lack the specific permissions required to view hidden user data. This issue affects CheckUser versions 1.45.0 through 1.45.1. An attacker with high-privileged access (but lacking specific suppression-viewing rights) could exploit this to identify accounts that have been hidden from the public. The vulnerability is addressed in version 1.45.2.

Affected products

  • Wikimedia Foundation CheckUser from 1.45.0 before 1.45.2

Timeline

  • 2025-12-01: disclosed: Issue reported internally via Phabricator
  • 2026-02-13: patched: Patch developed and reviewed
  • 2026-05-11: advisory: CVE-2026-34090 published

References

Related threats