CVE-2026-103442: MergeAccount PHP object injection via session-key substitution
Published Sep 30, 2026
·Updated
External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection.
This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki CentralAuth Extension=1.46, =1.45, =1.43
Event History
Sep 30, 2026
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which CentralAuth release lines are affected?
The issue affects the MediaWiki CentralAuth extension versions 1.46, 1.45, and 1.43.
2
What would an attacker need to exploit this issue?
The CVSS vector indicates network reachability, high privileges, user interaction, high attack complexity, and the presence of additional attack requirements. Exploitation is therefore not described as achievable by an unauthenticated attacker acting alone.