PatchSiren cyber security CVE debrief
CVE-2026-100378 Wikimedia Foundation CVE debrief
A Missing Authorization vulnerability in the Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from before 1.46.1, 1.45.5, 1.43.10. Defenders responsible for Mediawiki - Translate Extension deployments should assess exposure and prioritize verification of affected versions. The vulnerability allows unauthorized access to functionality, potentially impacting confidentiality and integrity. Verify affected versions to determine exposure and assess unauthorized access to functionality.
- Vendor
- Wikimedia Foundation
- Product
- Mediawiki - Translate Extension
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for Mediawiki - Translate Extension deployments should assess exposure and prioritize verification of affected versions.
Why it matters
Defenders should prioritize verifying affected versions and assessing exposure to the Missing Authorization vulnerability in Mediawiki - Translate Extension, as it allows unauthorized access to functionality.
- Verify affected versions to determine exposure
- Assess unauthorized access to functionality
- Implement compensating controls to restrict access
Technical summary
The Mediawiki - Translate Extension is vulnerable to Missing Authorization, allowing Accessing Functionality Not Properly Constrained by ACLs. This issue affects versions before 1.46.1, 1.45.5, 1.43.10. The vulnerability allows unauthorized access to functionality, potentially impacting confidentiality and integrity. Defenders should prioritize verifying affected versions and assessing exposure, as the vulnerability allows unauthorized access to functionality.
Defensive priority
Defenders should prioritize verifying affected versions and assessing exposure, as the vulnerability allows unauthorized access to functionality.
Recommended defensive actions
- Verify affected versions of Mediawiki - Translate Extension
- Assess exposure and unauthorized access to functionality
- Implement compensating controls to restrict access
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but additional information from official sources is needed to fully assess the issue.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100378 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100378
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100378 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100378
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gerrit.wikimedia.org/r/q/I9b74c849b223f18955b42779f5ffbd1e051e415c
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
-
Source reference
Unverified legacy reference
URL: https://phabricator.wikimedia.org/T433070
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.