Session Fixation Vulnerability in Wikimedia Foundation OAuth Software
CVE-2026-13707
NONE
What is CVE-2026-13707?
A session fixation vulnerability exists within the OAuth implementation of Wikimedia Foundation, allowing attackers to exploit session tokens. This issue can lead to unauthorized access as it allows an attacker to manipulate session identifiers for legitimate users, potentially compromising sensitive information and user accounts. The vulnerability affects several versions of the OAuth software, underscoring the importance of ensuring software is kept up-to-date to mitigate security risks.
Affected Version(s)
OAuth * <= 1.46.0, 1.45.4, 1.44.6, 1.43.9
