Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-100382: Mediawiki ExternalData extension lets attackers run code remotely

CVE-2026-100382 · published 1 day ago
Summary

The ExternalData add‑on for Mediawiki can be tricked into executing system commands without any authentication. This means an attacker could run arbitrary code on the server hosting your wiki, potentially stealing data or taking control. Upgrade the extension to version 3.7 or newer, or disable it until you can apply the update.

What to do
  • Update wikimedia foundation mediawiki - externaldata extension to version 3.7 or later.
Affected software
VendorProductAffected versions
wikimedia foundation mediawiki - externaldata extension < 3.7
Original advisory text
Unauthenticated remote code execution through wikitext in ExternalData
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection.

This issue affects Mediawiki - ExternalData Extension: from * before 3.7.
Severity
10.0 Critical
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published25 Sep 2026
Updated27 Sep 2026
First seen25 Sep 2026
Sources
CVE-2026-100382 · MITRE
Track software like this
Free during beta