CVE-2026-58026: $wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces
Published Jul 1, 2026
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Parser/Parser.Php.
This issue affects MediaWiki: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
5 affected components
Wikimedia Foundation MediaWiki>1.43.9<=1.46.0, =1.45.4, =1.44.6, =1.43.9
MediaWiki MediaWiki>=1.43.0<1.43.9
MediaWiki MediaWiki>=1.44.0<1.44.6
MediaWiki MediaWiki>=1.45.0<1.45.4
MediaWiki MediaWiki=1.46.0-rc0
Event History
Jul 1, 2026
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58026?
CVE-2026-58026 has a low severity rating of 0.
2
How do I fix CVE-2026-58026?
To mitigate CVE-2026-58026, upgrade MediaWiki to version 1.46.0 or later.
3
What kind of vulnerability is CVE-2026-58026?
CVE-2026-58026 is an exposure of sensitive information to an unauthorized actor vulnerability.
4
Which versions of MediaWiki are affected by CVE-2026-58026?
MediaWiki versions before 1.46.0, 1.45.4, 1.44.6, and 1.43.9 are affected by CVE-2026-58026.
5
What causes CVE-2026-58026?
CVE-2026-58026 is caused by a bypass in $wgNonincludableNamespaces allowing redirects in other namespaces.