CVE-2026-96872: WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions
Published Sep 23, 2026
·Updated
Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Mediawiki - WikiLambda Extension: before 1.47.0.
Affected Software
1 affected component
Wikimedia Foundation MediaWiki - WikiLambda Extension<1.47.0
Event History
Sep 23, 2026
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
DescriptionWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
MediaWiki installations using the WikiLambda extension before version 1.47.0 are affected. The issue applies on Linux, macOS, and Windows.
2
What condition is involved in exploitation?
The issue involves execution of a public function through nested Z825 compositions, allowing the unsaved-code permission restriction to be bypassed.