CVE-2026-58024: API identification of users on private wikis
Published Jul 1, 2026
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Api/ApiUserrights.Php.
This issue affects MediaWiki: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
5 affected components
Wikimedia Foundation MediaWiki><=1.46.0, ><=1.45.4, ><=1.44.6, ><=1.43.9
MediaWiki MediaWiki>=1.43.0<1.43.9
MediaWiki MediaWiki>=1.44.0<1.44.6
MediaWiki MediaWiki>=1.45.0<1.45.4
MediaWiki MediaWiki=1.46.0-rc0
Event History
Jul 1, 2026
CVE Published
via MITRE·02:34 PM
Data Sourced
via MITRE·02:34 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58024?
The severity of CVE-2026-58024 is classified as medium with a CVSS score of 5.1.
2
How do I fix CVE-2026-58024?
To fix CVE-2026-58024, upgrade to MediaWiki version 1.46.0 or later.
3
What information is exposed due to CVE-2026-58024?
CVE-2026-58024 exposes sensitive user information on private wikis to unauthorized actors.
4
Which versions of MediaWiki are affected by CVE-2026-58024?
CVE-2026-58024 affects MediaWiki versions before 1.46.0, including 1.45.4, 1.44.6, and 1.43.9.
5
What component of MediaWiki is vulnerable in CVE-2026-58024?
The vulnerable component associated with CVE-2026-58024 is ApiUserrights.php.