PatchSiren cyber security CVE debrief
CVE-2026-100379 Wikimedia Foundation CVE debrief
The CVE-2026-100379 issue involves an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the Wikimedia Foundation Wikipedia Android App. This vulnerability allows for Accessing/Intercepting/Modifying HTTP Cookies. The affected product is Wikipedia Android App: main. The CVSS score is 5.3, and the severity is MEDIUM. Defenders should assess exposure to potential cookie interception or modification. Verification of vulnerability status and potential exposure to cookie interception or modification is crucial.
- Vendor
- Wikimedia Foundation
- Product
- Wikipedia Android App
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-26
Who should care
Defenders responsible for the Wikipedia Android App and its users should assess exposure to potential cookie interception or modification. They should prioritize verifying the vulnerability status and assessing exposure. Operators, administrators, and security teams managing the Wikipedia Android App should review the vulnerability status and plan for potential security updates or patches.
Why it matters
The CVE-2026-100379 vulnerability in the Wikipedia Android App allows for Accessing/Intercepting/Modifying HTTP Cookies, which may lead to sensitive information exposure. Defenders should prioritize verifying the vulnerability status and assessing exposure.
- Verification of vulnerability status and potential exposure to cookie interception or modification
- Assessment of potential security updates or patches for the Wikipedia Android App
Technical summary
The CVE-2026-100379 vulnerability allows for Accessing/Intercepting/Modifying HTTP Cookies in the Wikipedia Android App. The CVSS score is 5.3, and the severity is MEDIUM. This issue affects Wikipedia Android App: main. Defenders should prioritize verifying the vulnerability status and assessing exposure to potential cookie interception or modification. The vulnerability may lead to sensitive information exposure.
Defensive priority
Defenders should prioritize verifying the vulnerability status of the Wikipedia Android App and assessing exposure to potential cookie interception or modification.
Recommended defensive actions
- Verify the vulnerability status of the Wikipedia Android App
- Assess exposure to potential cookie interception or modification
- Monitor for potential security updates or patches
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability. However, the source corpus lacks specific details on affected versions, exploitation, or remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-100379 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-100379
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-100379 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-100379
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/wikimedia/apps-android-wikipedia/pull/6768
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
-
Source reference
Unverified legacy reference
URL: https://phabricator.wikimedia.org/T433832
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.