Impact
The vulnerability is located in the API handling of user rights within MediaWiki. An unauthenticated endpoint can reveal the identities and permission settings of users. This disclosure of confidential information falls under the CWE‑200 category and carries a CVSS score of 5.1, indicating a moderate but non‑negligible impact on confidentiality.
Affected Systems
Any installation of Wikimedia Foundation MediaWiki running a version older than 1.46.0, 1.45.4, 1.44.6, or 1.43.9 is affected. Versions newer than these releases do not contain the flaw. The vulnerability applies to private wikis where the API endpoint is accessible.
Risk and Exploitability
Based on the description, the likely attack vector is an unauthenticated HTTP request to /api.php that calls the user rights endpoint; no additional credentials or local access are required. The vulnerability is not listed in CISA KEV catalog and its EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The moderate CVSS score reflects the potential for non‑destructive data leakage without requiring elevated privileges.
OpenCVE Enrichment
Debian DSA