CVE-2026-58033: "Total number of distinct authors" statistic at action=info does not exclude revisions where the author name was deleted
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki.
This vulnerability is associated with program files includes/Actions/InfoAction.Php.
This issue affects MediaWiki: from before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58033?
CVE-2026-58033 has a medium severity rating of 5.3.
How do I fix CVE-2026-58033?
To fix CVE-2026-58033, upgrade to MediaWiki version 1.46.0 or later, or apply the necessary patches provided by the Wikimedia Foundation.
What type of vulnerability is CVE-2026-58033?
CVE-2026-58033 is classified as an exposure of sensitive information to an unauthorized actor, also known as an info leak.
Which versions of MediaWiki are affected by CVE-2026-58033?
CVE-2026-58033 affects MediaWiki versions prior to 1.46.0, including 1.45.4, 1.44.6, and 1.43.9.
What can happen if CVE-2026-58033 is exploited?
If exploited, CVE-2026-58033 could expose distinct author statistics that were meant to be secured, potentially leading to unauthorized access to sensitive data.