PT-2026-99126 · Mediawiki · Externaldata Extension

·

CVE-2026-100382

·

Published

2026-09-25

·

Updated

2026-10-01

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Mediawiki - ExternalData Extension versions prior to 3.7
Description An OS Command Injection issue exists in the ExternalData extension, which allows unauthenticated remote code execution through wikitext. This occurs due to the improper neutralization of special elements used in an OS command.
Recommendations Update Mediawiki - ExternalData Extension to version 3.7 or later.

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100382

Affected Products

Externaldata Extension