๐Ÿ” CVE Alert

CVE-2026-103441

UNKNOWN 0.0

Unauthenticated arbitrary file deletion through Wikibase serialized entity parsing

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.

CWE CWE-502
Vendor the wikimedia foundation
Product mediawiki wikibase extension
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for the wikimedia foundation mediawiki wikibase extension

Be the first to know when new unknown vulnerabilities affecting the wikimedia foundation mediawiki wikibase extension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Wikimedia Foundation / MediaWiki Wikibase extension
1.46 1.45 1.43

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phabricator.wikimedia.org: https://phabricator.wikimedia.org/T435210 gerrit.wikimedia.org: https://gerrit.wikimedia.org/r/q/Id35bf747e48370e474d9b9444bd7520b24836e8d

Credits

๐Ÿ” Marco Paciaroni (BomboBombone)