OS Command Injection Vulnerability in Wikimedia Foundation Mediawiki Product
CVE-2026-100382

10CRITICAL

Key Information:

Vendor
CVE Published:
25 September 2026

What is CVE-2026-100382?

An OS Command Injection vulnerability exists in the ExternalData Extension for the Mediawiki platform, allowing attackers to inject and execute arbitrary OS commands. This vulnerability can be exploited by providing crafted input that is inadequately sanitized by the application, leading to potential unauthorized access or control over the system. Affected versions prior to 3.7 are particularly susceptible, highlighting the need for users to update to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

Mediawiki - ExternalData Extension * < 3.7

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SomeRandomDeveloper
.