CVE-2026-34092: Block UI elements in 'tools'-sidebar shows presence of an autoblocked IP
Published May 11, 2026
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
Affected Software
5 affected componentsFixes available
Wikimedia Foundation MediaWiki<1.43.7, <1.44.4, <1.45.2
MediaWiki MediaWiki<1.43.7
MediaWiki MediaWiki>=1.44.0<1.44.4
MediaWiki MediaWiki>=1.45.0<1.45.2
debian/mediawiki
1:1.35.13-1+deb11u21:1.35.13-1+deb11u61:1.39.17-1+deb12u21:1.43.8+dfsg-1~deb13u11:1.43.8+dfsg-2
Event History
May 11, 2026
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
May 27, 2026
Data Sourced
via Ubuntu·02:12 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·02:12 PM
Description
Data Sourced
via Debian·02:14 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-34092?
CVE-2026-34092 is classified as a moderate severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2026-34092?
To fix CVE-2026-34092, upgrade to MediaWiki version 1.43.8, 1.44.5, or 1.45.3, which contain the necessary patches.
3
What types of systems are affected by CVE-2026-34092?
CVE-2026-34092 affects installations of Wikimedia Foundation MediaWiki versions up to 1.43.7, 1.44.4, and 1.45.2.
4
What is the impact of CVE-2026-34092?
CVE-2026-34092 can lead to the exposure of sensitive information to unauthorized actors through a vulnerability in the tools-sidebar.
5
When was CVE-2026-34092 disclosed?
CVE-2026-34092 was disclosed in 2026, and users are urged to address the vulnerability promptly.