CVE-2025-11173 Details
Description
Vulnerability in Wikimedia Foundation OATHAuth. This vulnerability is associated with program files src/Special/OATHManage.Php. This issue affects OATHAuth: from * before 1.39.14, 1.43.4, 1.44.1.
A vulnerability exists in the Wikimedia Foundation OATHAuth extension, specifically in versions prior to 1.39.14, 1.43.4, and 1.44.1. The issue allows users to bypass the reauthentication requirement when enabling two-factor authentication (2FA). This is achieved by submitting a POST request to the OATH management page, exploiting a flaw in the reauthentication logic that does not apply to POST requests.
Users should update to OATHAuth versions 1.39.14, 1.43.4, or 1.44.1, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 3, 2026CISA-ADP
Assessed Feb 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://phabricator.wikimedia.org/T401862 | wikimedia-foundation | ExploitIssue TrackingTechnical DescriptionVendor |
| https://phabricator.wikimedia.org/T402094 | wikimedia-foundation | Issue TrackingVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Wikimedia Foundation OATHAuth | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | wikimedia-foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 3, 2026 | New CVE Received | wikimedia-foundation |
Volerion