CVE-2026-34091
Publication date 11 May 2026
Last updated 13 May 2026
Ubuntu priority
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mediawiki | 26.04 LTS resolute |
Fixed 1:1.43.8+dfsg-2
|
| 25.10 questing |
Vulnerable
|
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-34091
- https://phabricator.wikimedia.org/T411305
- https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1265651 (REL1_43)
- https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1265637 (master)
- https://lists.wikimedia.org/hyperkitty/list/wikitech-l@lists.wikimedia.org/thread/DIBLSBHISKX6NFRUFNOGZRVW42E7R2QP/