Junglewise Threat Intelligence

CVE-2026-34092: Wikimedia Foundation MediaWiki information disclosure in Skin.php

CVE-2026-34092 · Severity: high · CVSS 7.5 · Published 2026-05-11

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

MediaWiki, the software powering Wikipedia and many other wikis, contains a vulnerability that could allow unauthorized individuals to access sensitive information. This issue occurs within the system's skinning engine, which handles the visual layout of the site. If exploited, an attacker could potentially view data they are not permitted to see, which may impact user privacy or internal site operations.

Technical details

An information disclosure vulnerability (CWE-200) exists in MediaWiki's skinning system, specifically within the 'includes/Skin/Skin.php' file. The flaw allows an authenticated attacker with low privileges to potentially access sensitive data that should be restricted. Exploitation requires some level of user interaction and occurs over the network. The vulnerability affects multiple branches of MediaWiki and has been addressed in versions 1.43.7, 1.44.4, and 1.45.2.

Affected products

  • Wikimedia Foundation MediaWiki Before 1.43.7, 1.44.4, 1.45.2

Timeline

  • 2026-05-11: disclosed: CVE published to the NVD dataset

References

Related threats