CVE-2026-34086: AbuseFilter misuses ::userCanBitfield, exposing access-controlled information
Published May 11, 2026
·Updated
Vulnerability in Wikimedia Foundation AbuseFilter.
This issue affects AbuseFilter: from before 1.43.7, 1.44.4, 1.45.2.
Affected Software
1 affected component
Wikimedia Foundation AbuseFilter<1.43.7, <1.44.4, <1.45.2
Event History
May 11, 2026
CVE Published
via MITRE·02:35 PM
Data Sourced
via MITRE·02:35 PM
Description
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-34086?
CVE-2026-34086 has been classified with a high severity due to its potential for exposing sensitive access-controlled information.
2
How do I fix CVE-2026-34086?
To mitigate CVE-2026-34086, upgrade to Wikimedia Foundation AbuseFilter version 1.43.7 or later, 1.44.4 or later, or 1.45.2 or later.
3
What does CVE-2026-34086 affect?
CVE-2026-34086 affects the AbuseFilter component of Wikimedia Foundation software versions prior to 1.43.7, 1.44.4, and 1.45.2.
4
Is CVE-2026-34086 exploitable remotely?
Yes, CVE-2026-34086 can be exploited remotely, making it critical for users of the affected versions to take immediate action.
5
Who is responsible for the CVE-2026-34086 vulnerability?
The CVE-2026-34086 vulnerability was reported in the AbuseFilter maintained by the Wikimedia Foundation.