5.3

CVE-2026-0817

CampaignEvents API missing authorization exposes meeting and chat URLs

Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WikimediaCampaignevents Version1.39 SwPlatformmediawiki
WikimediaCampaignevents Version1.43 SwPlatformmediawiki
WikimediaCampaignevents Version1.44 SwPlatformmediawiki
WikimediaCampaignevents Version1.45 SwPlatformmediawiki
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.16
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://phabricator.wikimedia.org/T410560
Issue Tracking
https://gerrit.wikimedia.org/r/q/I7ed0049691258c8bd2555e599b9b88490fbe3358
Patch