Information Disclosure Vulnerability in MediaWiki by Wikimedia Foundation
CVE-2026-58036
2.1LOW
What is CVE-2026-58036?
An information disclosure vulnerability exists in Wikimedia Foundation's MediaWiki, which may allow unauthorized actors to access sensitive user information. This flaw is linked to specific program files, including ApiQueryAllUsers.php and ApiQueryUsers.php, as well as PermissionManager.php and UserGroupManager.php. As a result, attackers could potentially exploit this vulnerability to expose sensitive data, stressing the importance of timely updates and security reviews for affected versions of MediaWiki.
Affected Version(s)
MediaWiki 1.46.0-rc.0 < 1.46.0
