PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100378 Wikimedia Foundation CVE debrief

A Missing Authorization vulnerability in the Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from before 1.46.1, 1.45.5, 1.43.10. Defenders responsible for Mediawiki - Translate Extension deployments should assess exposure and prioritize verification of affected versions. The vulnerability allows unauthorized access to functionality, potentially impacting confidentiality and integrity. Verify affected versions to determine exposure and assess unauthorized access to functionality.

Vendor
Wikimedia Foundation
Product
Mediawiki - Translate Extension
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-26
Advisory published
2026-09-25
Advisory updated
2026-09-26

Who should care

Defenders responsible for Mediawiki - Translate Extension deployments should assess exposure and prioritize verification of affected versions.

Why it matters

Defenders should prioritize verifying affected versions and assessing exposure to the Missing Authorization vulnerability in Mediawiki - Translate Extension, as it allows unauthorized access to functionality.

  • Verify affected versions to determine exposure
  • Assess unauthorized access to functionality
  • Implement compensating controls to restrict access

Technical summary

The Mediawiki - Translate Extension is vulnerable to Missing Authorization, allowing Accessing Functionality Not Properly Constrained by ACLs. This issue affects versions before 1.46.1, 1.45.5, 1.43.10. The vulnerability allows unauthorized access to functionality, potentially impacting confidentiality and integrity. Defenders should prioritize verifying affected versions and assessing exposure, as the vulnerability allows unauthorized access to functionality.

Defensive priority

Defenders should prioritize verifying affected versions and assessing exposure, as the vulnerability allows unauthorized access to functionality.

Recommended defensive actions

  • Verify affected versions of Mediawiki - Translate Extension
  • Assess exposure and unauthorized access to functionality
  • Implement compensating controls to restrict access

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information from official sources is needed to fully assess the issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100378 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100378

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100378 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100378

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://gerrit.wikimedia.org/r/q/I9b74c849b223f18955b42779f5ffbd1e051e415c

    c4f26cc8-17ff-4c99-b5e2-38fc1793eacc

  • Source reference

    Unverified legacy reference

    URL: https://phabricator.wikimedia.org/T433070

    c4f26cc8-17ff-4c99-b5e2-38fc1793eacc

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.