CVE-2026-100377
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extension: 1.47.0-alpha. The issue has been remediated on the `master` branch.
- Published Sep 25, 2026
- CVSS 6.9 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available