PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58035 Wikimedia Foundation CVE debrief

CVE-2026-58035 is an Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in MediaWiki, a popular open-source wiki software. The vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue. This type of vulnerability allows attackers to inject malicious scripts into web pages, potentially leading to unauthorized actions or data theft. Users of MediaWiki may be affected by this vulnerability, especially if they have not applied the necessary patches or updates.

Vendor
Wikimedia Foundation
Product
MediaWiki
CVSS
NONE
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-01
Original CVE updated
2026-07-09
Advisory published
2026-07-01
Advisory updated
2026-07-09

Who should care

Users of MediaWiki, especially those with publicly accessible deployments, should be aware of this vulnerability and take steps to verify their exposure and apply patches or mitigations as needed. This includes MediaWiki administrators, security teams, and operators responsible for maintaining wiki instances.

Technical summary

CVE-2026-58035 is an Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in MediaWiki. The vulnerability has a CVSS score of null and a severity of NONE. It is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue. This vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users of the affected MediaWiki deployments. Affected users should review and apply vendor patches to mitigate this vulnerability.

Defensive priority

Medium priority due to limited information available on affected versions and configurations.

Recommended defensive actions

  • Review and apply vendor patches
  • Monitor for suspicious activity
  • Implement compensating controls
  • Verify affected MediaWiki deployments exist in managed environments
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

CVE-2026-58035 is an Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in MediaWiki. Evidence is limited; verify affected scope and vendor remediation. Limited information available on affected versions and configurations. Defenders should verify MediaWiki deployments and review vendor advisories for patching guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58035 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58035

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58035 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58035

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://phabricator.wikimedia.org/T428809

    c4f26cc8-17ff-4c99-b5e2-38fc1793eacc - Permissions Required

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.