OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100382

CRITICAL · CVSS 10 EPSS 0.95%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The ExternalData Extension of MediaWiki, prior to version 3.7, is vulnerable to OS Command Injection due to improper handling of special elements. This critical vulnerability allows attackers to execute arbitrary commands on the server, potentially compromising the entire system. Organizations using affected versions of MediaWiki should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-100382
Severity
CRITICAL
CVSS
10
EPSS
0.95%

Original NVD Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7.