PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-100379 Wikimedia Foundation CVE debrief

The CVE-2026-100379 issue involves an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the Wikimedia Foundation Wikipedia Android App. This vulnerability allows for Accessing/Intercepting/Modifying HTTP Cookies. The affected product is Wikipedia Android App: main. The CVSS score is 5.3, and the severity is MEDIUM. Defenders should assess exposure to potential cookie interception or modification. Verification of vulnerability status and potential exposure to cookie interception or modification is crucial.

Vendor
Wikimedia Foundation
Product
Wikipedia Android App
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-26
Advisory published
2026-09-25
Advisory updated
2026-09-26

Who should care

Defenders responsible for the Wikipedia Android App and its users should assess exposure to potential cookie interception or modification. They should prioritize verifying the vulnerability status and assessing exposure. Operators, administrators, and security teams managing the Wikipedia Android App should review the vulnerability status and plan for potential security updates or patches.

Why it matters

The CVE-2026-100379 vulnerability in the Wikipedia Android App allows for Accessing/Intercepting/Modifying HTTP Cookies, which may lead to sensitive information exposure. Defenders should prioritize verifying the vulnerability status and assessing exposure.

  • Verification of vulnerability status and potential exposure to cookie interception or modification
  • Assessment of potential security updates or patches for the Wikipedia Android App

Technical summary

The CVE-2026-100379 vulnerability allows for Accessing/Intercepting/Modifying HTTP Cookies in the Wikipedia Android App. The CVSS score is 5.3, and the severity is MEDIUM. This issue affects Wikipedia Android App: main. Defenders should prioritize verifying the vulnerability status and assessing exposure to potential cookie interception or modification. The vulnerability may lead to sensitive information exposure.

Defensive priority

Defenders should prioritize verifying the vulnerability status of the Wikipedia Android App and assessing exposure to potential cookie interception or modification.

Recommended defensive actions

  • Verify the vulnerability status of the Wikipedia Android App
  • Assess exposure to potential cookie interception or modification
  • Monitor for potential security updates or patches

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability. However, the source corpus lacks specific details on affected versions, exploitation, or remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-100379 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-100379

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-100379 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100379

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/wikimedia/apps-android-wikipedia/pull/6768

    c4f26cc8-17ff-4c99-b5e2-38fc1793eacc

  • Source reference

    Unverified legacy reference

    URL: https://phabricator.wikimedia.org/T433832

    c4f26cc8-17ff-4c99-b5e2-38fc1793eacc

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.