๐Ÿ” CVE Alert

CVE-2026-100379

UNKNOWN 0.0

Cross-request disclosure of CentralAuth cookies in Wikipedia Android App

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main.

CWE CWE-200
Vendor wikimedia foundation
Product wikipedia android app
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for wikimedia foundation wikipedia android app

Be the first to know when new unknown vulnerabilities affecting wikimedia foundation wikipedia android app are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Wikimedia Foundation / Wikipedia Android App
main

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phabricator.wikimedia.org: https://phabricator.wikimedia.org/T433832 github.com: https://github.com/wikimedia/apps-android-wikipedia/pull/6768

Credits

Vusal Isayev (GitHub: vusalGIT)