CVE-2026-103442
Awaiting Analysis Awaiting Analysis - Queue

Code Injection in MediaWiki CentralAuth Extension

Vulnerability report for CVE-2026-103442, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: wikimedia-foundation

Description

External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
the_wikimedia_foundation mediawiki_centralauth 1.46
the_wikimedia_foundation mediawiki_centralauth 1.45
the_wikimedia_foundation mediawiki_centralauth 1.43
wikimedia mediawiki_centralauth_extension 1.46
wikimedia mediawiki_centralauth_extension 1.45
wikimedia mediawiki_centralauth_extension 1.43

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-15 One or more system settings or configuration elements can be externally controlled by a user.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-103442 is a PHP object injection vulnerability in the CentralAuth extension's MergeAccount special page in MediaWiki. An authenticated user with specific permissions can manipulate a session key to inject a malicious PHP serialized object, potentially overwriting or truncating files accessible by the PHP process.

Detection Guidance

Check for unauthorized file modifications in MediaWiki directories, especially in cache, config, or extension folders. Review logs for suspicious activity related to Special:MergeAccount. Inspect PHP serialized objects in session data for unexpected structures.

Impact Analysis

This vulnerability allows an attacker to overwrite or truncate files like configuration, cache, logs, or extension data. It could damage system integrity and provide a foothold for further attacks, though standalone remote code execution is not claimed.

Mitigation Strategies

Disable Special:MergeAccount if not needed. Remove centralauth-merge permission from non-trusted users. Update MediaWiki CentralAuth extension to a patched version. Ensure PHP process write access is restricted to necessary directories only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103442. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart