Junglewise Threat Intelligence

CVE-2026-58517: Wikimedia MediaWiki WikiLambda Extension authentication bypass

CVE-2026-58517 · Severity: info · CVSS 6.9 · Published 2026-07-01

Technologies: The Wikimedia Foundation Mediawiki WikiLambda extension. Vendors: Wikimedia Foundation.

Executive brief

A vulnerability in the WikiLambda extension for MediaWiki allows blocked users to continue creating and editing WikiLambda objects. While these users are intended to be restricted from making changes to the wiki, a flaw in the authorization logic fails to verify their block status during specific API requests. This allows restricted individuals to bypass administrative bans and modify content, potentially leading to unauthorized data manipulation.

Technical details

An authentication bypass exists in the WikiLambda extension for MediaWiki due to improper authorization checks in the ZObjectAuthorization class and SpecialCreateObject component. The vulnerability stems from the application failing to manually verify user blocks when processing API requests (action=wikilambda_edit) and using an incorrect check (appliesToRight('createpage')) that returns null for standard blocks. An attacker with a blocked account can bypass these restrictions by interacting directly with the API to create or modify ZObjects. The issue is fixed in versions 1.43.9, 1.44.6, and 1.45.4 by implementing manual block validation within the authorization logic.

Affected products

  • The Wikimedia Foundation MediaWiki WikiLambda Extension before 1.43.9, 1.44.6, 1.45.4

Timeline

  • 2026-06-11: disclosed: Vulnerability reported via Phabricator
  • 2026-06-24: patched: Fix merged into master branch
  • 2026-07-01: advisory: CVE published and NVD record created

References