Executive brief
MediaWiki, the software powering Wikipedia and many other wikis, has a vulnerability that could allow unauthorized individuals to view sensitive information. This issue occurs within the system's content parsing component, which handles how wiki text is processed and displayed. While the specific impact is rated as low, it could potentially lead to the disclosure of data that should remain private. Organizations using MediaWiki should update to the latest patched versions to ensure their data remains protected.
Technical details
An Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability exists in Wikimedia Foundation MediaWiki within the 'includes/Parser/Parser.php' component. The flaw is triggered during the parsing of wiki content and requires a network-based attacker with low privileges and some level of user interaction to exploit. While the vendor-provided CVSS score is 0.0, the vulnerability is officially tracked as an information disclosure issue. The vulnerability is addressed in MediaWiki versions 1.46.0, 1.45.4, 1.44.6, and 1.43.9.
Affected products
- Wikimedia Foundation MediaWiki Before 1.46.0, 1.45.4, 1.44.6, 1.43.9
Timeline
- 2026-07-01: advisory: NVD publication date