Description
Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files.

This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote code execution via unauthenticated file deletion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a deserialization flaw in the MediaWiki Wikibase extension, allowing an attacker to supply crafted serialized data that is processed without authentication. The flaw can be used to delete arbitrary files on the server or to execute arbitrary code found in non‑executable files, leading to loss of data integrity and service availability. This weakness is identified as CWE‑502, Deserialization of Untrusted Data.

Affected Systems

The Wikimedia Foundation’s MediaWiki Wikibase extension versions 1.43, 1.45, and 1.46 are affected. Any site running these versions of the extension is vulnerable and can be reached by unauthenticated users.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity that could lead to remote code execution or significant data loss. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and its ability to alter critical files make it readily exploitable. Attackers can target any public or internal instance of MediaWiki that accepts serialized entity input, potentially compromising the file system or the entire web application.

Generated by OpenCVE AI on September 30, 2026 at 17:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched or later version of the MediaWiki Wikibase extension (e.g., 1.47 or newer) if available.
  • If an update is not feasible, disable the Wikibase extension or block the ability to submit serialized entity data.
  • Implement Web Application Firewall rules or input sanitization to reject malicious serialized payloads and monitor for unauthorized file deletion activity.

Generated by OpenCVE AI on September 30, 2026 at 17:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.
Title Unauthenticated arbitrary file deletion through Wikibase serialized entity parsing
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:P/S:N/AU:Y/R:I/V:C/RE:M/U:Red'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-09-30T15:59:42.361Z

Reserved: 2026-09-30T15:41:01.270Z

Link: CVE-2026-103441

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:09.860

Modified: 2026-09-30T16:27:40.143

Link: CVE-2026-103441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data