CVE-2026-96872 - WikiLambda public function execution bypasses the unsaved-code permission through nested Z825 compositions
CVE ID :CVE-2026-96872
Published : Sept. 23, 2026, 6:50 p.m. | 20 minutes ago
Description :Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - WikiLambda Extension: before 1.47.0.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 23, 2026, 6:50 p.m. | 20 minutes ago
Description :Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - WikiLambda Extension: before 1.47.0.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...