Description
Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation.

This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.
Published: 2026-09-30
Score: 1.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The PageTriage extension contains a data query flaw that permits the retrieval of suppressed reviewer usernames. This exposes confidential editorial metadata and personal identifiers, violating reviewer privacy and the integrity of the moderation process. The vulnerability is a direct information elicitation weakness that can reveal sensitive data to an internal or external adversary. Repeated exploitation could erode trust in the system’s confidentiality guarantees. The fixed CWE for the defect is CWE-202.

Affected Systems

MediaWiki PageTriage extension versions 1.46, 1.45, and 1.43 are affected. The flaw is present on MediaWiki instances that enable PageTriage for content moderation. Any site deploying these specific extension releases without remediation is susceptible to the disclosure.

Risk and Exploitability

The CVSS score of 1.2 reflects a low severity impact, and the EPSS score is not available, implying a limited known exploitation trend. The flaw does not require special credentials; the attack vector is inferred to be possible through unauthenticated or minimally privileged access to PageTriage listings. While the risk of immediate compromise is modest, accidental or intentional disclosure undermines the privacy of reviewers and may impair the reputation of the site.

Generated by OpenCVE AI on September 30, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the MediaWiki PageTriage extension to a fixed release or apply the vendor patch that corrects the data query flaw.
  • Configure ACLs or extension settings to restrict or disable the display of suppressed reviewer usernames, ensuring only authorized roles can view that information.
  • Monitor and audit PageTriage access logs to identify unusual or unauthorized requests that could indicate exploitation attempts.

Generated by OpenCVE AI on September 30, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.
Title pagetriagelist discloses suppressed reviewer usernames
Weaknesses CWE-202
References
Metrics cvssV4_0

{'score': 1.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-30T20:01:01.418Z

Reserved: 2026-09-30T15:41:01.269Z

Link: CVE-2026-103440

cve-icon Vulnrichment

Updated: 2026-09-30T18:47:03.152Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T18:18:16.727

Modified: 2026-09-30T21:17:08.950

Link: CVE-2026-103440

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:30:18Z

Weaknesses
  • CWE-202

    Exposure of Sensitive Information Through Data Queries