CVE-2026-34093: Special:UserRights allows viewing user rights from private wiki
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34093?
CVE-2026-34093 is classified as a vulnerability allowing exposure of sensitive information to unauthorized actors.
How do I fix CVE-2026-34093?
To fix CVE-2026-34093, update your MediaWiki installation to version 1.43.8, 1.44.5, or 1.45.3 or later.
What versions of MediaWiki are affected by CVE-2026-34093?
CVE-2026-34093 affects MediaWiki versions up to and including 1.43.7, 1.44.4, and 1.45.2.
What type of information is exposed in CVE-2026-34093?
CVE-2026-34093 exposes user rights information that should be kept private from unauthorized actors.
Who is responsible for fixing CVE-2026-34093?
The responsibility for fixing CVE-2026-34093 lies with the administrators of affected MediaWiki installations.