Junglewise Threat Intelligence

CVE-2026-58029: Wikimedia Foundation MediaWiki improper authentication in account management components

CVE-2026-58029 · Severity: info · CVSS 5.3 · Published 2026-07-01

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

A security vulnerability exists in MediaWiki, the software used to power Wikipedia and many other collaborative websites. The flaw is located in the components responsible for managing user accounts and authentication data. If exploited, it could allow an attacker to interfere with how accounts are linked or modified, potentially impacting the integrity of user authentication.

Technical details

An improper authentication vulnerability (CWE-287) exists in MediaWiki's authentication handling logic. The issue is specifically located within several API modules and Special pages, including ApiChangeAuthenticationData, ApiLinkAccount, ApiRemoveAuthenticationData, SpecialLinkAccounts, and SpecialUnlinkAccounts. The vulnerability requires user interaction (UI:P) and can be triggered over the network. It allows for a partial impact on the confidentiality and integrity of the authentication process. The issue has been addressed in versions 1.46.0, 1.45.4, 1.44.6, and 1.43.9.

Affected products

  • Wikimedia Foundation MediaWiki before 1.46.0, 1.45.4, 1.44.6, 1.43.9

Timeline

  • 2026-07-01: advisory: NVD published the CVE record.

References

Related threats