Junglewise Threat Intelligence

CVE-2026-58034: Wikimedia Foundation CheckUser XSS in blockConnectedTempAccountsField

CVE-2026-58034 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Wikimedia Foundation CheckUser. Vendors: Wikimedia Foundation.

Executive brief

A security vulnerability exists in the Wikimedia CheckUser extension, a tool used by wiki administrators to investigate disruptive behavior and sockpuppetry. This flaw could allow a malicious actor to execute unauthorized scripts in the browser of another user, potentially leading to the theft of session information or unauthorized actions. The impact is limited as it requires high-level administrative privileges and specific user interaction to trigger.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Wikimedia Foundation CheckUser extension within the 'blockConnectedTempAccountsField.Vue' component. The root cause is improper neutralization of input during web page generation, specifically affecting the temporary accounts module. An attacker with high privileges (PR:H) could potentially inject malicious scripts that execute when an administrative user interacts with the affected UI component. The vulnerability was identified in version 1.46.0-rc.0 and is addressed in version 1.46.0.

Affected products

  • Wikimedia Foundation CheckUser 1.46.0-rc.0 to 1.46.0

Timeline

  • 2026-07-01: advisory: CVE-2026-58034 published by Wikimedia Foundation
  • 2026-07-01: patched: Fixed in version 1.46.0

References

Related threats