PatchSiren cyber security CVE debrief
CVE-2026-58035 Wikimedia Foundation CVE debrief
CVE-2026-58035 is an Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in MediaWiki, a popular open-source wiki software. The vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue. This type of vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft. Users of MediaWiki may be affected by this vulnerability, especially if they have not applied the necessary patches or updates.
- Vendor
- Wikimedia Foundation
- Product
- MediaWiki
- CVSS
- NONE
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-01
- Original CVE updated
- 2026-07-09
- Advisory published
- 2026-07-01
- Advisory updated
- 2026-07-09
Who should care
Users of MediaWiki, especially those with publicly accessible deployments, should be aware of this vulnerability and take steps to verify their exposure and apply patches or mitigations as needed. This includes MediaWiki administrators, security teams, and operators responsible for maintaining wiki instances.
Technical summary
CVE-2026-58035 is an Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in MediaWiki. The vulnerability has a CVSS score of null and a severity of NONE. It is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue. This vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users of the affected MediaWiki deployments. Affected users should review and apply vendor patches to mitigate this vulnerability.
Defensive priority
Medium priority due to limited information available on affected versions and configurations.
Recommended defensive actions
- Review and apply vendor patches
- Monitor for suspicious activity
- Implement compensating controls
- Verify affected MediaWiki deployments exist in managed environments
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
CVE-2026-58035 is an Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in MediaWiki. Evidence is limited; verify affected scope and vendor remediation. Limited information available on affected versions and configurations. Defenders should verify MediaWiki deployments and review vendor advisories for patching guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58035 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58035
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58035 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58035
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://phabricator.wikimedia.org/T428809
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.