CVE-2026-96879
Received Received - Intake

Improper Information Exposure in MediaWiki FlaggedRevs Extension

Vulnerability report for CVE-2026-96879, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: wikimedia-foundation

Description

Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wikimedia mediawiki_flaggedrevs 1.46.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-212 The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper removal of sensitive information before storage or transfer issue in the Wikimedia Foundation's MediaWiki FlaggedRevs extension up to version 1.46.0. It allows sensitive data to remain accessible when it should have been deleted or obscured.

Impact Analysis

The vulnerability could expose sensitive information to unauthorized users if the FlaggedRevs extension fails to properly remove it. This may lead to data leaks, privacy breaches, or unauthorized access to confidential content stored or transferred by the MediaWiki system.

Compliance Impact

This vulnerability could lead to non-compliance with data protection regulations like GDPR or HIPAA by failing to properly remove or protect sensitive information. Organizations using the affected extension may face legal penalties, fines, or reputational damage due to unauthorized data exposure.

Mitigation Strategies

Update the FlaggedRevs extension to version 1.46.0 or later to address the improper removal of sensitive information vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96879. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart