MediaWiki 1.44.x < 1.44.4 Multiple Vulnerabilities

medium Web App Scanning Plugin ID 115326

Synopsis

MediaWiki 1.44.x < 1.44.4 Multiple Vulnerabilities

Description

According to its self-reported version number, the instance of MediaWiki hosted on the remote web server is prior to 1.43.7, 1.44.x prior to 1.44.4 or 1.45.x prior to 1.45.2. It is, therefore, affected by a number of vulnerabilities as follows.

- Block UI elements in the 'tools' sidebar reveal the presence of an autoblocked IP. (CVE-2026-34092)

- RecentChanges entries expose suppressed content via generated log page HTML. (CVE-2026-34088)

- User localization is leaked by AbuseFilter + EventStream. (CVE-2026-34091)

- Suggested investigations do not handle suppressed usernames. (CVE-2026-34090)

- The Users API leaks whether privileged users have their user groups disabled for lack of 2FA. (CVE-2026-34087)

- Special:UserRights allows viewing user rights from a private wiki. (CVE-2026-34093)

- AbuseFilter misuses ::userCanBitfield, exposing access-controlled information. (CVE-2026-34086)

- The customized help link for the page protection indicator is relative to the subpage name. (CVE-2026-34094)

- A memory leak in Scribunto causes runJobs.php to run out of memory. (CVE-2026-34089)

- action=raw with a Special:Mypage subpage responds with text/html on a javascript request. (CVE-2026-34095)

- The Notifications (Echo) API can be used by any OAuth tool. (CVE-2026-5266)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to MediaWiki version 1.44.4 or later.

See Also

https://lists.wikimedia.org/hyperkitty/list/[email protected]/thread/DIBLSBHISKX6NFRUFNOGZRVW42E7R2QP/

Plugin Details

Severity: Medium

ID: 115326

Type: Version Based

Published: 7/28/2026

Updated: 7/28/2026

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.5

CVSS v2

Risk Factor: High

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-34087

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Score Source: CVE-2026-34089

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-34091

Vulnerability Information

CPE: cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/11/2026

Reference Information

CVE: CVE-2026-34086, CVE-2026-34087, CVE-2026-34088, CVE-2026-34089, CVE-2026-34090, CVE-2026-34091, CVE-2026-34092, CVE-2026-34093, CVE-2026-34094, CVE-2026-34095, CVE-2026-5266

CWE: 20, 200, 400, 668, 79, 862

OWASP: 2010-A2, 2010-A4, 2010-A6, 2010-A8, 2013-A3, 2013-A4, 2013-A5, 2013-A7, 2013-A9, 2017-A5, 2017-A6, 2017-A7, 2017-A9, 2021-A1, 2021-A3, 2021-A6, 2025-A1, 2025-A5, 2025-A6

WASC: Cross-Site Scripting, Denial of Service, Improper Input Handling, Information Leakage, Insufficient Authorization

CAPEC: 10, 101, 104, 108, 109, 110, 116, 120, 13, 135, 136, 14, 147, 153, 169, 182, 197, 209, 22, 224, 23, 230, 231, 24, 250, 261, 267, 28, 285, 287, 290, 291, 292, 293, 294, 295, 296, 297, 298, 299, 3, 300, 301, 302, 303, 304, 305, 306, 307, 308, 309, 31, 310, 312, 313, 317, 318, 319, 320, 321, 322, 323, 324, 325, 326, 327, 328, 329, 330, 42, 43, 45, 46, 47, 472, 473, 492, 497, 508, 52, 53, 573, 574, 575, 576, 577, 588, 59, 591, 592, 60, 616, 63, 64, 643, 646, 651, 67, 7, 71, 72, 73, 78, 79, 8, 80, 81, 83, 85, 88, 9

DISA STIG: APSC-DV-000460, APSC-DV-000480, APSC-DV-002400, APSC-DV-002490, APSC-DV-002560, APSC-DV-002630

HIPAA: 164.306(a)(1), 164.306(a)(2), 164.312(a)(1), 164.312(a)(2)(i), 164.312(e)

ISO: 27001-A.12.6.1, 27001-A.13.1.1, 27001-A.13.1.3, 27001-A.13.2.1, 27001-A.14.1.2, 27001-A.14.1.3, 27001-A.14.2.5, 27001-A.18.1.3, 27001-A.6.2.2, 27001-A.9.1.2, 27001-A.9.4.1, 27001-A.9.4.4, 27001-A.9.4.5

NIST: sp800_53-AC-3, sp800_53-AC-4, sp800_53-CM-6b, sp800_53-SC-5, sp800_53-SI-10, sp800_53-SI-15

OWASP API: 2019-API7, 2023-API8

OWASP ASVS: 4.0.2-14.2.1, 4.0.2-5.1.3, 4.0.2-5.3.3, 4.0.2-8.3.4

PCI-DSS: 3.2-2.2, 3.2-6.2, 3.2-6.5, 3.2-6.5.7, 3.2-6.5.8