PT-2026-54635 · Wikimedia Foundation+2 · Oauth+1

CVE-2026-13707

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OAuth versions prior to 1.46.1 OAuth version 1.45.4 OAuth version 1.44.6 OAuth version 1.43.9
Description A session fixation issue exists in the Wikimedia Foundation OAuth implementation, specifically within the src/Backend/MWOAuthServer.Php file. Session fixation is a method where an attacker provides a valid session identifier to a user and then waits for the user to authenticate, allowing the attacker to hijack the authenticated session.
Recommendations Update OAuth to a version newer than 1.46.0. Update OAuth to a version newer than 1.45.4. Update OAuth to a version newer than 1.44.6. Update OAuth to a version newer than 1.43.9.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13707

Affected Products

Oauth
Mediawiki