๐Ÿ” CVE Alert

CVE-2026-103446

UNKNOWN 0.0

WikiLambda exposes anonymous execution of unsaved Abstract Wikipedia fragments

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Authorization bypass through User-Controlled key vulnerability in The Wikimedia Foundation MediaWiki WikiLambda extension allows Authentication Bypass. This issue affects MediaWiki WikiLambda extension: 1.46.

CWE CWE-639
Vendor the wikimedia foundation
Product mediawiki wikilambda extension
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for the wikimedia foundation mediawiki wikilambda extension

Be the first to know when new unknown vulnerabilities affecting the wikimedia foundation mediawiki wikilambda extension are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Wikimedia Foundation / MediaWiki WikiLambda extension
1.46

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
phabricator.wikimedia.org: https://phabricator.wikimedia.org/T435086 gerrit.wikimedia.org: https://gerrit.wikimedia.org/r/q/If2c05b109672fc65f63372f86c768859dc6639fd

Credits

๐Ÿ” Marco Paciaroni (BomboBombone)