CVE-2025-6926
Security Authentication Bypass in CentralAuth
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
La vulnerabilidad de autenticación incorrecta en Wikimedia Foundation Mediawiki - CentralAuth Extension permite: Omitir la autenticación. Este problema afecta a Mediawiki - CentralAuth Extension: desde 1.39.X antes de 1.39.13, desde 1.42.X antes de 1.42.7, desde 1.43.X antes de 1.43.2.
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting, information disclosure, HTML injection or incorrect tracking of authentication events. For the stable distribution (bookworm), these problems have been fixed in version 1:1.39.13-1~deb12u1.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-06-30 CVE Reserved
- 2025-07-03 CVE Published
- 2025-07-03 CVE Updated
- 2025-07-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
- CAPEC-178: Cross-Site Flashing
References (2)
URL | Tag | Source |
---|---|---|
https://gerrit.wikimedia.org/r/c/mediawiki/core/+/1165117 | ||
https://phabricator.wikimedia.org/T389010 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wikimedia Foundation Search vendor "Wikimedia Foundation" | Mediawiki - CentralAuth Extension Search vendor "Wikimedia Foundation" for product "Mediawiki - CentralAuth Extension" | >= 1.39.0 < 1.39.13 Search vendor "Wikimedia Foundation" for product "Mediawiki - CentralAuth Extension" and version " >= 1.39.0 < 1.39.13" | en |
Affected
| ||||||
Wikimedia Foundation Search vendor "Wikimedia Foundation" | Mediawiki - CentralAuth Extension Search vendor "Wikimedia Foundation" for product "Mediawiki - CentralAuth Extension" | >= 1.42.0 < 1.42.7 Search vendor "Wikimedia Foundation" for product "Mediawiki - CentralAuth Extension" and version " >= 1.42.0 < 1.42.7" | en |
Affected
| ||||||
Wikimedia Foundation Search vendor "Wikimedia Foundation" | Mediawiki - CentralAuth Extension Search vendor "Wikimedia Foundation" for product "Mediawiki - CentralAuth Extension" | >= 1.43.0 < 1.43.2 Search vendor "Wikimedia Foundation" for product "Mediawiki - CentralAuth Extension" and version " >= 1.43.0 < 1.43.2" | en |
Affected
|