CVE-2026-34090: Suggested investigations: Handle suppressed usernames
Published May 11, 2026
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue affects CheckUser: from 1.45.0 before 1.45.2.
Affected Software
2 affected components
Wikimedia Foundation CheckUser>=1.45.0<1.45.2
MediaWiki Checkuser Mediawiki>=1.45.0<1.45.2
Remediation
Patch Available
Event History
May 11, 2026
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34090?
The severity of CVE-2026-34090 is classified as medium.
2
What specific versions of CheckUser are affected by CVE-2026-34090?
CVE-2026-34090 affects versions of CheckUser from 1.45.0 before 1.45.2.
3
How do I fix CVE-2026-34090?
To fix CVE-2026-34090, you should update CheckUser to version 1.45.2 or later.
4
What type of vulnerability is CVE-2026-34090?
CVE-2026-34090 is a vulnerability that exposes sensitive information to an unauthorized actor.
5
What system does CVE-2026-34090 affect?
CVE-2026-34090 affects the Wikimedia Foundation CheckUser software.