CVE-2026-103440
CVE-2026-103440 is a low-severity vulnerability with a CVSS 4.0 base score of 1.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-202.
Key facts
- Severity: Low (CVSS 4.0 base score 1.2)
- EPSS exploit prediction: 0% (18th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-202
- Published:
- Last modified:
Description
Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.
Frequently asked questions
- What is CVE-2026-103440?
- Exposure of sensitive information through data queries vulnerability in The Wikimedia Foundation MediaWiki PageTriage extension allows Information Elicitation. This issue affects MediaWiki PageTriage extension: 1.46, 1.45, and 1.43.
- How severe is CVE-2026-103440?
- CVE-2026-103440 has a CVSS 4.0 base score of 1.2, rated low severity.
- Is CVE-2026-103440 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (18th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-103440?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-103440 published?
- CVE-2026-103440 was published on 2026-09-30.
References
- https://gerrit.wikimedia.org/r/q/I4bdd5f5be95ed5d02c504784fb31da4e5de59da6
- https://phabricator.wikimedia.org/T435623
Other CWE-202 vulnerabilities
- CVE-2021-32743 — High (CVSS 8.8): Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and…
- CVE-2024-2088 — High (CVSS 8.5): The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in…
- CVE-2025-25205 — High (CVSS 8.2): Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a…
- CVE-2026-33530 — High (CVSS 7.7): InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with…
- CVE-2026-30778 — High (CVSS 7.5): The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of…
- CVE-2025-69200 — High (CVSS 7.5): phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can…