CVE-2026-58029: Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata
Vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, includes/Api/ApiLinkAccount.Php, includes/Api/ApiRemoveAuthenticationData.Php, includes/Specials/SpecialLinkAccounts.Php, includes/Specials/SpecialUnlinkAccounts.Php.
This issue affects MediaWiki: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58029?
CVE-2026-58029 has a medium severity score of 5.3 according to the CVSS.
How do I fix CVE-2026-58029?
To mitigate CVE-2026-58029, update your Wikimedia Foundation MediaWiki software to the latest patched version.
What systems are affected by CVE-2026-58029?
CVE-2026-58029 affects the Wikimedia Foundation MediaWiki software.
What kind of attack does CVE-2026-58029 enable?
CVE-2026-58029 allows for full account takeover through vulnerabilities in BotPasswords and OAuth mechanisms.
When was CVE-2026-58029 published?
CVE-2026-58029 was published on July 1, 2026.