Description
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
Published: 2026-09-14
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

An issue exists in the CheckUser extension for MediaWiki that causes the Special:CheckUserLog page to display usernames that should remain hidden. The flaw results in accidental leakage of user identities, compromising the privacy of users tracked through CheckUser. The weakness is identified as CWE-669, Improper Restriction of Operations within a Component, indicating a failure to enforce intended access controls on log data. The disclosure of hidden usernames may allow an attacker to link otherwise anonymized user activity, undermining user anonymity and potentially facilitating social engineering or targeted attacks.

Affected Systems

The vulnerability affects installations of the CheckUser extension for MediaWiki through version 1.39.3. Any MediaWiki instance using a CheckUser extension up to and including 1.39.3, regardless of other MediaWiki components, is susceptible. The specific vendor and product is MediaWiki’s CheckUser extension, and the affected releases are any builds that incorporate the extension prior to its remediation in later releases.

Risk and Exploitability

Because the exploit requires access to the Special:CheckUserLog page, the attack surface is limited to users who have the rights to view that page; this inference is made as the advisory does not explicitly state the required permissions, but it is likely that only administrators or users with the MediaWiki privileged ‘checkuser’ right can access it. The CVSS base score of 3.1 indicates a low severity; however, the risk is amplified in environments where user anonymity is a requirement. The EPSS score is < 1%, indicating a very low exploitation probability at the time of the advisory, meaning a competent attacker could simply request the page. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation at the time of reporting. The likely attack vector is through an authenticated privileged user accessing the Special:CheckUserLog page; this is inferred from the context rather than explicitly stated.

Generated by OpenCVE AI on September 15, 2026 at 17:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the CheckUser extension to a version newer than 1.39.3 that contains the fix for hidden‑username disclosure.
  • If a timely upgrade is not possible, restrict access to Special:CheckUserLog by revoking the ‘checkuser’ right from all but essential administrators and apply least‑privilege principles.
  • Audit log access logs regularly to detect any unauthorized attempts to view hidden usernames and adjust permissions accordingly.

Generated by OpenCVE AI on September 15, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Hidden Usernames Leak in MediaWiki CheckUser Extension

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Hidden Usernames Leak in MediaWiki CheckUser Extension

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediawiki
Mediawiki checkuser
Weaknesses CWE-669
CPEs cpe:2.3:a:mediawiki:checkuser:*:*:*:*:*:*:*:*
Vendors & Products Mediawiki
Mediawiki checkuser
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Mon, 14 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.
References

Subscriptions

Mediawiki Checkuser
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:16:59.396Z

Reserved: 2023-06-29T00:00:00.000Z

Link: CVE-2023-37252

cve-icon Vulnrichment

Updated: 2026-09-14T16:16:53.651Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T05:16:57.580

Modified: 2026-09-16T19:31:54.210

Link: CVE-2023-37252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-669

    Incorrect Resource Transfer Between Spheres