CVE-2026-39937
Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects non release branches.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L
- EPSS probability
- 0.26%
- CWE
- CWE-212
- Published
- 2026-04-07
- Last modified
- 2026-04-10
Affected products
- The Wikimedia Foundation Mediawiki - CentralAuth Extension
- The Wikimedia Foundation Mediawiki - CentralAuth Extension
- The Wikimedia Foundation Mediawiki - CentralAuth Extension
- The Wikimedia Foundation Mediawiki - CentralAuth Extension
- The Wikimedia Foundation Mediawiki - CentralAuth Extension
- The Wikimedia Foundation Mediawiki - CentralAuth Extension
- The Wikimedia Foundation Mediawiki - CentralAuth Extension
Weakness type
Related vulnerabilities
- CVE-2026-86740 — Snipe-IT before 8.7.0 Attachment Deletion Reports Success While File Remains
- CVE-2026-82069 — Improper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster Router
- CVE-2026-53604 — nebula-mesh: CA private key not zeroized on web mobile-bundle error paths
- CVE-2026-78658 — IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an information disclosure vulnerability
- CVE-2026-85094 — The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin...
- CVE-2026-62900 — .NET Information Disclosure Vulnerability
- CVE-2024-5300 — AppArmor Base Profile Misconfiguration in snapd Permits Confined Snaps Unauthorized Access to Hashed Passwords via systemd-userdbd
- CVE-2026-15811 — Kronosnet: kronosnet: encryption key exposure in memory after cryptographic configuration changes