CVE-2026-34088
published 2026-05-11CVE-2026-34088: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.29%
21.1th percentile
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.43.8+dfsg-1 (forky) | mediawiki 1:1.43.8+dfsg-1 (forky) |
| mediawiki | mediawiki | < 1.43.7 | 1.43.7 |
| mediawiki | mediawiki | >= 1.44.0 < 1.44.4 | 1.44.4 |
| mediawiki | mediawiki | >= 1.45.0 < 1.45.2 | 1.45.2 |
| ubuntu | mediawiki | — | — |
| wikimedia_foundation | mediawiki | >= * < 1.43.7, 1.44.4, 1.45.2 | 1.43.7, 1.44.4, 1.45.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.01.3LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:X/RE:M/U:X
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MediaWiki vulnerabilities
vendor_ubuntu·2026-05-27·CVSS 5.1
CVE-2026-34092 [MEDIUM] MediaWiki vulnerabilities
Title: MediaWiki vulnerabilities
Summary: MediaWiki could be made to expose sensitive information over the
network.
It was discovered that MediaWiki incorrectly handled group membership
visibility in the OATHAuth extension. An authenticated attacker could
use this issue to determine if other users had two-factor authentication
enabled. (CVE-2026-34087)
It was discovered that MediaWiki incorrectly handled suppressed log entry
titles in the RecentChanges list. An unauthenticated attacker could use
this issue to view titles of deleted or suppressed pages that should be hidden.
(CVE-2026-34088)
It was discovered that MediaWiki incorrectly handled resource loading timing
information. An attacker could use this issue to determine if certain pages
existed on a wiki. (CVE-2026-34092)
Instruct
Debian
CVE-2026-34088: mediawiki
vendor_debian·2026
CVE-2026-34088 CVE-2026-34088: mediawiki
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.43.8+dfsg-1)
sid: resolved (fixed in 1:1.43.8+dfsg-1)
trixie: open
GHSA
GHSA-wpmg-m9mx-w7pj: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki
ghsa_unreviewed·2026-05-11
CVE-2026-34088 [LOW] CWE-200 GHSA-wpmg-m9mx-w7pj: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34088 mediawiki: RecentChanges entries expose suppressed content via generated log page html [fedora-all]
bugzilla·2026-05-14·CVSS 1.3
CVE-2026-34088 [LOW] CVE-2026-34088 mediawiki: RecentChanges entries expose suppressed content via generated log page html [fedora-all]
CVE-2026-34088 mediawiki: RecentChanges entries expose suppressed content via generated log page html [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34088 mediawiki: RecentChanges entries expose suppressed content via generated log page html
bugzilla·2026-05-11·CVSS 1.3
CVE-2026-34088 [LOW] CVE-2026-34088 mediawiki: RecentChanges entries expose suppressed content via generated log page html
CVE-2026-34088 mediawiki: RecentChanges entries expose suppressed content via generated log page html
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
2026-05-11
Published