CVE-2026-34094: Customized help link for page protection indicator is relative to subpage name, because the link target is missing the "/wiki/" prefix
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34094?
CVE-2026-34094 is classified as a vulnerability affecting the Wikimedia Foundation MediaWiki software, though the specific severity level has not been detailed in the current reports.
How do I fix CVE-2026-34094?
To fix CVE-2026-34094, ensure that your MediaWiki installation is updated to version 1.45.3 or later, which includes the patch for this vulnerability.
What versions of MediaWiki are affected by CVE-2026-34094?
CVE-2026-34094 affects MediaWiki versions up to 1.45.2, as well as 1.44.4 and 1.43.7.
What are the consequences of CVE-2026-34094?
The consequences of CVE-2026-34094 may include potential misleading help links within the user interface that could hinder navigation on affected MediaWiki pages.
Where can I find more information about CVE-2026-34094?
More information about CVE-2026-34094 can be found in the security advisories and bug reports provided by the Wikimedia Foundation.