OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103441

HIGH · CVSS 7.2 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The MediaWiki Wikibase extension versions 1.46, 1.45, and 1.43 are vulnerable to a deserialization of untrusted data flaw that enables the execution of arbitrary code within non-executable files. This high-severity vulnerability poses a significant risk to systems utilizing these versions, potentially allowing attackers to compromise the integrity and security of the application. Organizations using the affected versions should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-103441
Severity
HIGH
CVSS
7.2
EPSS
0.28%

Original NVD Description

Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.