CVE-2026-58517: Blocked users can create and edit WikiLambda objects
Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass.
This issue affects Mediawiki - WikiLambda Extension: from before 1.43.9,1.44.6,1.45.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58517?
CVE-2026-58517 has a medium severity rating of 6.9 according to the CVSS v3.0 scoring system.
How do I fix CVE-2026-58517?
To mitigate CVE-2026-58517, users should upgrade the MediaWiki - WikiLambda Extension to versions 1.43.9, 1.44.6, or 1.45.4 or later.
What type of vulnerability is CVE-2026-58517?
CVE-2026-58517 is classified as an improper neutralization of input terminators vulnerability, leading to authentication bypass.
Which software is affected by CVE-2026-58517?
CVE-2026-58517 affects the Wikimedia Foundation MediaWiki - WikiLambda Extension in versions prior to 1.43.9, 1.44.6, and 1.45.4.
What is the potential impact of CVE-2026-58517?
The potential impact of CVE-2026-58517 includes allowing blocked users to create and edit WikiLambda objects, which undermines user access controls.