CVE-2026-58517: CWE-288 Authentication bypass using an alternate path or channel in The Wikimedia Foundation Mediawiki - WikiLambda Extension
Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-58517 in the Mediawiki WikiLambda Extension arises from improper neutralization of input terminators, which leads to an authentication bypass (CWE-288). This allows an attacker to circumvent authentication controls by exploiting alternate paths or channels. The affected versions include all releases prior to 1.43.9, 1.44.6, and 1.45.4. The Wikimedia Foundation provides this as a cloud service, implying that remediation is managed server-side by the vendor. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges or user interaction required, with low to low impact on confidentiality, integrity, availability, scope, and impact metrics.
Potential Impact
Successful exploitation of this vulnerability could allow an unauthenticated attacker to bypass authentication controls in the WikiLambda Extension of Mediawiki. This could lead to unauthorized access to functionality or data protected by authentication. However, the impact is rated medium severity with limited impact on confidentiality, integrity, and availability as per the CVSS vector.
Mitigation Recommendations
Since this is a cloud-hosted service managed by The Wikimedia Foundation, remediation is handled by the vendor. Users should ensure they are using versions 1.43.9, 1.44.6, 1.45.4 or later, as these versions address the vulnerability. Check the official Wikimedia Foundation advisories for confirmation of patch deployment and further guidance. No additional user action is required if the service is fully managed and updated by the vendor.
CVE-2026-58517: CWE-288 Authentication bypass using an alternate path or channel in The Wikimedia Foundation Mediawiki - WikiLambda Extension
Description
Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.
CVSS v4.0
Score 6.9medium
Affected software
pkg:github/wikimedia/mediawiki-wikilambda-extensionRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-58517 in the Mediawiki WikiLambda Extension arises from improper neutralization of input terminators, which leads to an authentication bypass (CWE-288). This allows an attacker to circumvent authentication controls by exploiting alternate paths or channels. The affected versions include all releases prior to 1.43.9, 1.44.6, and 1.45.4. The Wikimedia Foundation provides this as a cloud service, implying that remediation is managed server-side by the vendor. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no privileges or user interaction required, with low to low impact on confidentiality, integrity, availability, scope, and impact metrics.
Potential Impact
Successful exploitation of this vulnerability could allow an unauthenticated attacker to bypass authentication controls in the WikiLambda Extension of Mediawiki. This could lead to unauthorized access to functionality or data protected by authentication. However, the impact is rated medium severity with limited impact on confidentiality, integrity, and availability as per the CVSS vector.
Mitigation Recommendations
Since this is a cloud-hosted service managed by The Wikimedia Foundation, remediation is handled by the vendor. Users should ensure they are using versions 1.43.9, 1.44.6, 1.45.4 or later, as these versions address the vulnerability. Check the official Wikimedia Foundation advisories for confirmation of patch deployment and further guidance. No additional user action is required if the service is fully managed and updated by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- wikimedia-foundation
- Date Reserved
- 2026-07-01T03:40:44.768Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a455e5b27e9c79719f17aef
Added to database: 07/01/2026, 18:37:15 UTC
Last enriched: 07/10/2026, 09:47:50 UTC
Last updated: 08/15/2026, 00:41:14 UTC
Views: 138
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.