Impact
The WikiLambda extension in MediaWiki is vulnerable to an authorization bypass through a user‑controlled key, allowing unauthenticated users to execute unsaved Abstract Wikipedia fragments. This flaw directly leads to authentication bypass, giving attackers access to execute code or commands without valid credentials, and is categorized as CWE‑639.
Affected Systems
The vulnerability affects the Wikimedia Foundation MediaWiki WikiLambda extension, specifically version 1.46. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity, while the lack of a KEV listing and unreported EPSS score suggest no widespread exploitation yet, but the remote nature of the flaw means any user can craft a request to trigger the bypass. Attackers could exploit this by setting a malicious user‑controlled key to inject or run arbitrary code within the wiki environment, potentially compromising confidentiality, integrity, or availability of the content.
OpenCVE Enrichment