CVE-2025-6592
Authentication Bypass Vulnerability in Wikimedia AbuseFilter AuthManager
Publication date: 2026-02-02
Last updated on: 2026-02-04
Assigner: wikimedia-foundation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wikimedia_foundation | abusefilter | From fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 (inc) to 1.43.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Wikimedia Foundation AbuseFilter, specifically in the program file includes/auth/AuthManager.Php. It affects versions before 1.43.2 and version 1.44.0. The exact nature of the vulnerability is not detailed in the provided information.
How can this vulnerability impact me? :
The impact details of this vulnerability are not provided in the available information. The CVSS base score is low (2.1), indicating a low severity, but specific impacts are not described.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
There is no information available regarding how this vulnerability affects compliance with standards such as GDPR or HIPAA.