๐Ÿ” CVE Alert

CVE-2026-103442

UNKNOWN 0.0

MergeAccount PHP object injection via session-key substitution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.

CWE CWE-15
Vendor the wikimedia foundation
Product mediawiki centralauth extension
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for the wikimedia foundation mediawiki centralauth extension

Be the first to know when new unknown vulnerabilities affecting the wikimedia foundation mediawiki centralauth extension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Wikimedia Foundation / MediaWiki CentralAuth extension
1.46 1.45 1.43

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phabricator.wikimedia.org: https://phabricator.wikimedia.org/T435624 gerrit.wikimedia.org: https://gerrit.wikimedia.org/r/q/I9c59e5c3f217c1eaa02934a076604049bac2b025

Credits

๐Ÿ” Marco Paciaroni (BomboBombone)