Improper Information Handling in Wikimedia Foundation's MediaWiki FlaggedRevs Extension
CVE-2026-96879

6.9MEDIUM

What is CVE-2026-96879?

The MediaWiki FlaggedRevs extension developed by the Wikimedia Foundation exhibits a vulnerability that fails to adequately remove sensitive information prior to its storage or transfer. This oversight can potentially lead to unauthorized access to confidential data, highlighting the necessity for vigilant data management practices within the extension's operational framework. Prompt action is recommended to safeguard sensitive information from exposure.

Affected Version(s)

Mediawiki - FlaggedRevs extension 0 <= 1.46.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.