Junglewise Threat Intelligence

CVE-2026-58033: Wikimedia Foundation MediaWiki information disclosure in InfoAction

CVE-2026-58033 · Severity: info · CVSS 5.3 · Published 2026-07-01

Technologies: Wikimedia Foundation MediaWiki. Vendors: Wikimedia Foundation.

Executive brief

MediaWiki, the software powering Wikipedia and many other wikis, contains a vulnerability that could allow unauthorized individuals to view sensitive information. This issue occurs within the page information component, potentially exposing data that should be restricted. While the impact is limited to information disclosure, it could compromise the privacy of wiki operations or user metadata.

Technical details

An information disclosure vulnerability (CWE-200) exists in MediaWiki's 'includes/Actions/InfoAction.php' component. The flaw allows a remote attacker to access sensitive data that should be restricted to authorized users. The attack requires minimal technical skill and some user interaction, as indicated by the CVSS UI:P (User Interaction Required) metric. Successful exploitation results in a loss of confidentiality (VC:L). The issue has been addressed in versions 1.46.0, 1.45.4, 1.44.6, and 1.43.9.

Affected products

  • Wikimedia Foundation MediaWiki Before 1.46.0, 1.45.4, 1.44.6, 1.43.9

Timeline

  • 2026-07-01: advisory: NVD publication date

References

Related threats