Junglewise Threat Intelligence

CVE-2026-34094: Wikimedia Foundation MediaWiki JavaScript injection in page protection indicators

CVE-2026-34094 · Severity: low · CVSS 3.8 · Published 2026-05-11

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

A vulnerability exists in MediaWiki, the software used to power Wikipedia and other collaborative wikis, specifically within its page protection indicator system. This flaw could allow a user with administrative privileges to bypass security restrictions and insert unauthorized JavaScript code into pages. If exploited, this could lead to unauthorized actions being performed in the context of other users' sessions, potentially compromising sensitive administrative functions.

Technical details

A vulnerability in MediaWiki's 'includes/Page/Article.php' component arises from a failure to validate the link target for customized help links in page protection indicators. When the '$wgEnableProtectionIndicators' setting is enabled, the software fails to properly prefix or validate the help page link, causing it to be relative to subpage names. This lack of validation allows an attacker with administrative privileges (but lacking 'interface-admin' rights) to inject JavaScript into the page via the 'MediaWiki:Protection-editautoreviewprotected-helppage' message. The issue affects MediaWiki versions prior to 1.43.7, 1.44.4, and 1.45.2. Patches have been released to validate these link targets.

Affected products

  • Wikimedia Foundation MediaWiki before 1.43.7, 1.44.4, 1.45.2

Timeline

  • 2026-02-01: disclosed: Issue reported via Phabricator
  • 2026-02-15: patched: Security patches developed for release branches
  • 2026-03-25: advisory: Task resolved and CVE assigned
  • 2026-05-11: other: NVD publication date

References

Related threats