CVE-2026-96872

Published: Set 23, 2026 Last Modified: Set 24, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,9
Source: c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Mediawiki - WikiLambda Extension: before 1.47.0.

280

Improper Handling of Insufficient Permissions or Privileges

Draft
Common Consequences
Security Scopes Affected:
Other
Potential Impacts:
Other Alter Execution Logic
Applicable Platforms
All platforms may be affected
View CWE Details
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/WikiLambda/+/1326392
https://phabricator.wikimedia.org/T435085