CVE-2026-58025

Published Jul 1, 2026

Last updated 25 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-58025 is a deserialization of untrusted data vulnerability found in Wikimedia Foundation MediaWiki. This flaw is associated with specific program files, including `includes/Import/WikiImporter.Php`, `includes/Import/WikiRevision.Php`, and `includes/Logging/LogEntryBase.Php`. The vulnerability affects MediaWiki versions prior to 1.46.0, 1.45.4, 1.44.6, and 1.43.9. An attacker with `importupload` or `import` permissions (typically the `sysop` group) can exploit this by crafting a malicious XML import file containing serialized PHP objects in the `params` fields. This can lead to arbitrary object instantiation and potentially remote code execution through gadget chains.

Description
Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Source
c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
NVD status
Analyzed
Products
mediawiki

Risk scores

CVSS 4.0

Type
Secondary
Base score
5.9
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
CWE-94

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.