Description
Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass.

This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.
Published: 2026-07-01
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, an Improper Neutralization of Input Terminators flaw, lets blocked users bypass authentication controls and create or edit WikiLambda objects. As a result, users who should be denied access can modify or add protected content, compromising the integrity of the WikiLambda data. This is a classic authentication bypass scenario identified as CWE‑288.

Affected Systems

The issue affects MediaWiki’s WikiLambda Extension for all releases prior to 1.43.9, 1.44.6, and 1.45.4. The affected environment is the Wikimedia Foundation’s MediaWiki platform where the WikiLambda feature is enabled.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. Because the EPSS score is <1%, exploitation likelihood is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack beyond the normal authentication mechanism are noted in the description, so the exploit is expected to be straightforward for an attacker who can gain blocked status or impersonate a blocked account.

Generated by OpenCVE AI on July 21, 2026 at 13:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WikiLambda Extension to version 1.43.9 or later, 1.44.6 or later, or 1.45.4 or later, before the vulnerability is addressed.
  • If a patch is unavailable or cannot to access the WikiLambda editing interface by revoking the relevant wiki rights for blocked accounts.
  • Continuously monitor wiki logs for unexpected creation or modification of WikiLambda objects and enforce stricter audit trails for content edits to detect unauthorized activity.

Generated by OpenCVE AI on July 21, 2026 at 13:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Wikimedia
Wikimedia mediawiki-wikilambda Extension
Vendors & Products Wikimedia
Wikimedia mediawiki-wikilambda Extension

Fri, 03 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-140
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

threat_severity

Critical


Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.
Title Blocked users can create and edit WikiLambda objects
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Wikimedia Mediawiki-wikilambda Extension
cve-icon MITRE

Status: PUBLISHED

Assigner: wikimedia-foundation

Published:

Updated: 2026-07-01T18:35:06.496Z

Reserved: 2026-07-01T03:40:44.768Z

Link: CVE-2026-58517

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Critical

Publid Date: 2026-07-01T18:23:02Z

Links: CVE-2026-58517 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:45:03Z

Weaknesses
  • CWE-140

    Improper Neutralization of Delimiters

  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel