CVE-2026-58028: Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation CentralAuth.
This vulnerability is associated with program files includes/Api/ApiFormatBase.Php, includes/Api/ApiHelp.Php, includes/ResourceLoader/Module.Php, includes/Hooks/Handlers/PageDisplayHookHandler.Php, includes/LogFormatter/PermissionChangeLogFormatter.Php.
This issue affects MediaWiki: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9; CentralAuth: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58028?
The severity of CVE-2026-58028 is classified as low with a CVSS score of 4.0.
What type of vulnerability is CVE-2026-58028?
CVE-2026-58028 is an XSS (Cross-site Scripting) vulnerability due to improper neutralization of input during web page generation.
How do I fix CVE-2026-58028?
To mitigate CVE-2026-58028, ensure that proper input validation and sanitization mechanisms are implemented in the affected API outputs.
What applications are affected by CVE-2026-58028?
CVE-2026-58028 affects Wikimedia Foundation MediaWiki and Wikimedia Foundation CentralAuth.
When was CVE-2026-58028 published?
CVE-2026-58028 was published on July 1, 2026.