Junglewise Threat Intelligence

CVE-2026-58024: Wikimedia Foundation MediaWiki information disclosure in ApiUserrights

CVE-2026-58024 · Severity: info · CVSS 5.1 · Published 2026-07-01

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

MediaWiki, the software used to power Wikipedia and other collaborative wikis, contains a vulnerability that could allow unauthorized users to view sensitive information. An attacker with a basic user account could potentially access data they are not permitted to see by interacting with the user rights management system. This could lead to the exposure of internal configuration or user-related details, though it does not allow for the modification of data or site takeover.

Technical details

An information disclosure vulnerability (CWE-200) exists in MediaWiki's ApiUserrights.php component. The flaw allows a remote attacker with low privileges (PR:L) to access sensitive information that should be restricted. Exploitation requires some level of user interaction (UI:P) and is facilitated through the API. The vulnerability affects multiple branches of MediaWiki and has been addressed in versions 1.46.0, 1.45.4, 1.44.6, and 1.43.9.

Affected products

  • Wikimedia Foundation MediaWiki Before 1.46.0, 1.45.4, 1.44.6, 1.43.9

Timeline

  • 2026-07-01: advisory: CVE published by Wikimedia Foundation
  • 2026-07-01: disclosed: NVD record published

References

Related threats