CVE-2026-34091: User localization leaked by AbuseFilter + EventStream
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34091?
The severity of CVE-2026-34091 is considered to be high due to the exposure of sensitive user localization information.
How do I fix CVE-2026-34091?
To fix CVE-2026-34091, upgrade MediaWiki to version 1.43.7 or later, or to version 1.44.4 or later, or to version 1.45.2 or later.
What systems are affected by CVE-2026-34091?
CVE-2026-34091 affects MediaWiki versions prior to 1.43.7, 1.44.4, and 1.45.2.
What kind of information is leaked in CVE-2026-34091?
CVE-2026-34091 leaks user localization data, which can potentially expose sensitive information to unauthorized actors.
Who is responsible for fixing CVE-2026-34091 vulnerabilities?
It is the responsibility of the system administrators and users running affected versions of MediaWiki to apply the necessary updates to mitigate CVE-2026-34091.