Junglewise Threat Intelligence

CVE-2026-34093: Wikimedia Foundation MediaWiki sensitive information exposure in SpecialUserRights

CVE-2026-34093 · Severity: medium · CVSS 5.3 · Published 2026-05-11

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

MediaWiki, the software used to power Wikipedia and other collaborative wikis, contains a security flaw in its user rights management component. This vulnerability could allow an unauthorized individual to view sensitive information that should normally be restricted. While it requires a low-level user account and some user interaction to exploit, it could lead to the exposure of private administrative or user data.

Technical details

An information disclosure vulnerability (CWE-200) exists in MediaWiki's 'SpecialUserRights.php' component. The flaw allows an authenticated attacker with low privileges to access sensitive data that should be restricted to higher-level administrators. Exploitation requires network access and a degree of user interaction. The issue has been addressed in MediaWiki versions 1.43.7, 1.44.4, and 1.45.2. An attacker successfully leveraging this vulnerability can gain unauthorized insight into user rights configurations or associated metadata.

Affected products

  • Wikimedia Foundation MediaWiki Before 1.43.7, 1.44.4, 1.45.2

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory

References

Related threats