CVE-2026-58517 Details
Description
Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.
A vulnerability allowing authentication bypass has been identified in the Wikimedia Foundation's MediaWiki WikiLambda Extension, affecting versions prior to 1.43.9, 1.44.6, and 1.45.4. This issue arises from improper handling of input terminators, which allows blocked users to create and edit WikiLambda objects. The vulnerability exists because the extension does not correctly check user block status when processing API requests, enabling blocked users to bypass restrictions and manipulate WikiLambda content.
Users can update to MediaWiki WikiLambda Extension versions 1.43.9, 1.44.6, or 1.45.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gerrit.wikimedia.org/r/c/1305376 | wikimedia-foundation | Issue Tracking |
| https://phabricator.wikimedia.org/T428833 | wikimedia-foundation | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | wikimedia-foundation |
Affected Products
| Product | Versions |
|---|---|
| mediawiki mediawiki | >= 1.43.0, < 1.43.9 >= 1.44.0, < 1.44.6 >= 1.45.0, < 1.45.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | Reanalysis | [email protected] |
| Jul 9, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | New CVE Received | wikimedia-foundation |
| Jul 1, 2026 | CVE Modified | CISA-ADP |