CVE-2026-58026
published 2026-07-01CVE-2026-58026: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files…
PriorityP430medium5.7CVSS 3.1
AVNACLPRLUIRSUCHINAN
EPSS
0.37%
29.3th percentile
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Parser/Parser.Php.
This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 1.43.0 < 1.43.9 | 1.43.9 |
| mediawiki | mediawiki | >= 1.44.0 < 1.44.6 | 1.44.6 |
| mediawiki | mediawiki | >= 1.45.0 < 1.45.4 | 1.45.4 |
| wikimedia_foundation | mediawiki | >= * < 1.46.0, 1.45.4, 1.44.6, 1.43.9 | 1.46.0, 1.45.4, 1.44.6, 1.43.9 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv4.00.0NONECVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Wikimedia MediaWiki up to 1.45.x/1.45.3/1.44.5/1.43.8 Parser.Php information disclosure (Nessus ID 324024)
vuldb·2026-07-04
CVE-2026-58026 [NONE] Wikimedia MediaWiki up to 1.45.x/1.45.3/1.44.5/1.43.8 Parser.Php information disclosure (Nessus ID 324024)
A vulnerability marked as problematic has been reported in Wikimedia MediaWiki up to 1.45.x/1.45.3/1.44.5/1.43.8. This affects an unknown part of the file includes/Parser/Parser.Php. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-58026. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
ghsa_unreviewed·2026-07-01
CVE-2026-58026 [LOW] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Parser/Parser.Php.
This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-01
Published