Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-100382: Mediawiki ExternalData extension lets attackers run code remotely
CVE-2026-100382 · published 1 day ago
Summary
The ExternalData add‑on for Mediawiki can be tricked into executing system commands without any authentication. This means an attacker could run arbitrary code on the server hosting your wiki, potentially stealing data or taking control. Upgrade the extension to version 3.7 or newer, or disable it until you can apply the update.
What to do
- Update wikimedia foundation mediawiki - externaldata extension to version 3.7 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wikimedia foundation | mediawiki - externaldata extension | < 3.7 |
Original advisory text
Unauthenticated remote code execution through wikitext in ExternalData
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection.
This issue affects Mediawiki - ExternalData Extension: from * before 3.7.
This issue affects Mediawiki - ExternalData Extension: from * before 3.7.
Severity
10.0
Critical
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta