OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103442

HIGH · CVSS 7.2 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The MediaWiki CentralAuth extension versions 1.43, 1.45, and 1.46 are vulnerable to a code injection attack due to external control over system or configuration settings. This vulnerability could allow an attacker to execute arbitrary code, potentially compromising the integrity and security of the affected systems. Organizations using these specific versions of the MediaWiki CentralAuth extension should prioritize immediate patching to mitigate the risk.

CVE
CVE-2026-103442
Severity
HIGH
CVSS
7.2
EPSS
0.28%

Original NVD Description

External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.