OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100240

CRITICAL · CVSS 9.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Mediawiki - TemplateSandbox Extension prior to versions 1.46.1, 1.45.5, and 1.43.10 contains a missing authorization vulnerability that allows unauthorized access to functionalities not properly constrained by Access Control Lists (ACLs). This could lead to potential exploitation by attackers to manipulate or access sensitive features within the application. Organizations using affected versions of Mediawiki should prioritize patching to mitigate the risk of unauthorized access.

CVE
CVE-2026-100240
Severity
CRITICAL
CVSS
9.1
EPSS
0.30%

Original NVD Description

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - TemplateSandbox Extension: from * before 1.46.1, 1.45.5, 1.43.10.