Executive brief
A vulnerability in MediaWiki, the software used to power Wikipedia and other wikis, could allow unauthorized individuals to access sensitive information. This issue occurs within the system's user management and API components, potentially exposing data that should be restricted. While the risk is considered low, it could lead to a minor breach of privacy for users on the platform.
Technical details
An information disclosure vulnerability (CWE-200) exists in Wikimedia Foundation MediaWiki. The flaw is located within several core components, including ApiQueryAllUsers.php, ApiQueryUsers.php, PermissionManager.php, and UserGroupManager.php. An attacker with low privileges could potentially exploit these API endpoints to retrieve sensitive user information that should not be accessible. The attack requires network access and involves some level of user interaction or specific environmental conditions (AC:H). The issue affects versions starting from 1.46.0-rc.0 and is addressed in version 1.46.0.
Affected products
- Wikimedia Foundation MediaWiki 1.46.0-rc.0 to 1.46.0
Timeline
- 2026-07-01: disclosed
- 2026-07-01: advisory