CVE-2026-58027
published 2026-07-01CVE-2026-58027: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.23%
14.4th percentile
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter.
This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php.
This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mediawiki | mediawiki | — | — |
| mediawiki | mediawiki | >= 1.43.0 < 1.43.9 | 1.43.9 |
| mediawiki | mediawiki | >= 1.44.0 < 1.44.6 | 1.44.6 |
| mediawiki | mediawiki | >= 1.45.0 < 1.45.4 | 1.45.4 |
| wikimedia_foundation | abusefilter | >= * < 1.46.0, 1.45.4, 1.44.6, 1.43.9 | 1.46.0, 1.45.4, 1.44.6, 1.43.9 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Wikimedia AbuseFilter up to 1.45.x/1.45.3/1.44.5/1.43.8 QueryAbuseFilters.Php information disclosure (Nessus ID 324028)
vuldb·2026-07-04·CVSS 5.3
CVE-2026-58027 [MEDIUM] Wikimedia AbuseFilter up to 1.45.x/1.45.3/1.44.5/1.43.8 QueryAbuseFilters.Php information disclosure (Nessus ID 324028)
A vulnerability described as problematic has been identified in Wikimedia AbuseFilter up to 1.45.x/1.45.3/1.44.5/1.43.8. This vulnerability affects unknown code of the file includes/Api/QueryAbuseFilters.Php. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-58027. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter.
ghsa_unreviewed·2026-07-01
CVE-2026-58027 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter.
This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php.
This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-01
Published