Junglewise Threat Intelligence

CVE-2026-34091: Wikimedia Foundation MediaWiki sensitive information disclosure

CVE-2026-34091 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

A vulnerability in MediaWiki, the software used to power Wikipedia and many other corporate wikis, allows unauthorized individuals to access sensitive information. This could lead to the exposure of internal data or configuration details that should remain private. Organizations using MediaWiki should update to the latest patched versions to protect their data integrity and privacy.

Technical details

A CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerability exists in Wikimedia Foundation MediaWiki. The flaw allows a remote, unauthenticated attacker to access information that is intended to be restricted. The vulnerability is reachable over the network without user interaction. Patches have been released in versions 1.43.7, 1.44.4, and 1.45.2 to address this information disclosure.

Affected products

  • Wikimedia Foundation MediaWiki before 1.43.7, 1.44.4, 1.45.2

Timeline

  • 2026-05-11: advisory: Initial disclosure by Wikimedia Foundation

References

Related threats