Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies.

This issue affects Wikipedia Android App: main.
Published: 2026-09-25
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Data Exposure
Action: Patch
AI Analysis

Impact

The vulnerability stems from a flaw in the Wikipedia Android App that allows cross‑request disclosure of CentralAuth cookies. This flaw permits an attacker to read, intercept, or modify HTTP cookies that contain authentication tokens, exposing sensitive user session data. The weakness is a classic information‑leak scenario (CWE‑200).

Affected Systems

The impacted product is the Wikimedia Foundation’s Wikipedia Android App, version "main" following the latest code base changes. Specific version numbers are not listed, so all builds of the main branch that include the affected source code are considered vulnerable.

Risk and Exploitability

The CVSS score of 5.3 describes a moderate risk that could compromise user authentication information if exploited. EPSS data is not available, and the vulnerability is not in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is a network or local attacker who can observe HTTP traffic or trigger the app to send a request that leaks cookie data. However, the description does not confirm a publicly exploitable trigger, so the practical exploitation window may be limited to scenarios where the attacker can observe or influence inter‑app network traffic or interfere with the app’s request handling.

Generated by OpenCVE AI on September 25, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Wikipedia Android App to the latest version that includes the CentralAuth cookie protection fix
  • If an update is not immediately possible, clear the app’s cache and stored credentials to revoke exposed session tokens
  • Use a trusted network or VPN and keep the app’s data on secure storage to reduce the risk of network‑based cookie interception

Generated by OpenCVE AI on September 25, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main.
Title Cross-request disclosure of CentralAuth cookies in Wikipedia Android App
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-25T20:54:08.355Z

Reserved: 2026-09-25T19:28:11.982Z

Link: CVE-2026-100379

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-25T21:17:21.910

Modified: 2026-09-25T21:17:21.910

Link: CVE-2026-100379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T23:00:15Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor