CVE-2026-58027: QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI
Published Jul 1, 2026
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter.
This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php.
This issue affects AbuseFilter: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
5 affected components
Wikimedia Foundation AbuseFilter>*<=1.46.0, >*<=1.45.4, >*<=1.44.6, >*<=1.43.9
MediaWiki MediaWiki>=1.43.0<1.43.9
MediaWiki MediaWiki>=1.44.0<1.44.6
MediaWiki MediaWiki>=1.45.0<1.45.4
MediaWiki MediaWiki=1.46.0-rc0
Event History
Jul 1, 2026
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-58027?
The severity of CVE-2026-58027 is medium with a CVSS score of 5.3.
2
How does CVE-2026-58027 affect users?
CVE-2026-58027 allows unauthorized actors to view the hit count of private filters, exposing sensitive information.
3
What versions of AbuseFilter are affected by CVE-2026-58027?
CVE-2026-58027 affects AbuseFilter versions before 1.46.0, as well as 1.45.4, 1.44.6, and 1.43.9.
4
How do I fix CVE-2026-58027?
To fix CVE-2026-58027, upgrade AbuseFilter to version 1.46.0 or later.
5
What type of vulnerability is CVE-2026-58027 classified as?
CVE-2026-58027 is classified as an exposure of sensitive information to an unauthorized actor.