CVE-2026-13707: Session fixation attacks on improperly configured OAuth 1.0a tools
Session fixation vulnerability in Wikimedia Foundation OAuth.
This vulnerability is associated with program files src/Backend/MWOAuthServer.Php.
This issue affects OAuth: from through 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MWOAuthServer.Php (Wikimedia Foundation OAuth)to a version that resolves this vulnerability.Fixed in 1.46.0 - Upgrade
Upgrade
MWOAuthServer.Php (Wikimedia Foundation OAuth)to a version that resolves this vulnerability.Fixed in 1.45.4 - Upgrade
Upgrade
MWOAuthServer.Php (Wikimedia Foundation OAuth)to a version that resolves this vulnerability.Fixed in 1.44.6 - Upgrade
Upgrade
MWOAuthServer.Php (Wikimedia Foundation OAuth)to a version that resolves this vulnerability.Fixed in 1.43.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13707?
The severity of CVE-2026-13707 is rated as low with a CVSS score of 4.0.
How do I fix CVE-2026-13707?
To fix CVE-2026-13707, ensure proper configuration of OAuth 1.0a tools and update to the patched versions of MediaWiki.
What impact can CVE-2026-13707 have on my application?
CVE-2026-13707 can expose applications to session fixation attacks, allowing unauthorized access under certain conditions.
Which software versions are affected by CVE-2026-13707?
CVE-2026-13707 affects MediaWiki versions prior to 1.46.0, specifically 1.45.4, 1.44.6, and 1.43.9.
Is CVE-2026-13707 specific to any particular software?
Yes, CVE-2026-13707 is specifically related to vulnerabilities in Wikimedia Foundation's OAuth implemented in MediaWiki.