CVE-2026-34087
published 2026-05-11CVE-2026-34087: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue affects OATHAuth: from * before 1.43.7…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.27%
18.7th percentile
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth.
This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.43.8+dfsg-1 (forky) | mediawiki 1:1.43.8+dfsg-1 (forky) |
| mediawiki | mediawiki | < 1.43.7 | 1.43.7 |
| mediawiki | mediawiki | >= 1.44.0 < 1.44.4 | 1.44.4 |
| mediawiki | mediawiki | >= 1.45.0 < 1.45.2 | 1.45.2 |
| ubuntu | mediawiki | — | — |
| wikimedia_foundation | oathauth | >= * < 1.43.7, 1.44.4, 1.45.2 | 1.43.7, 1.44.4, 1.45.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:X
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MediaWiki vulnerabilities
vendor_ubuntu·2026-05-27·CVSS 5.1
CVE-2026-34092 [MEDIUM] MediaWiki vulnerabilities
Title: MediaWiki vulnerabilities
Summary: MediaWiki could be made to expose sensitive information over the
network.
It was discovered that MediaWiki incorrectly handled group membership
visibility in the OATHAuth extension. An authenticated attacker could
use this issue to determine if other users had two-factor authentication
enabled. (CVE-2026-34087)
It was discovered that MediaWiki incorrectly handled suppressed log entry
titles in the RecentChanges list. An unauthenticated attacker could use
this issue to view titles of deleted or suppressed pages that should be hidden.
(CVE-2026-34088)
It was discovered that MediaWiki incorrectly handled resource loading timing
information. An attacker could use this issue to determine if certain pages
existed on a wiki. (CVE-2026-34092)
Instruct
Debian
CVE-2026-34087: mediawiki
vendor_debian·2026
CVE-2026-34087 CVE-2026-34087: mediawiki
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.43.8+dfsg-1)
sid: resolved (fixed in 1:1.43.8+dfsg-1)
trixie: open
GHSA
GHSA-6fcc-jw5f-pvm9: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth
ghsa_unreviewed·2026-05-11
CVE-2026-34087 [MEDIUM] CWE-200 GHSA-6fcc-jw5f-pvm9: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth.
This issue affects OATHAuth: from * before 1.43.7, 1.44.4, 1.45.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-11
Published