PT-2026-33201 · Wikimedia Foundation+3 · Oathauth+1

Published

2026-04-03

·

Updated

2026-05-14

·

CVE-2026-34087

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OATHAuth versions prior to 1.43.7 OATHAuth versions prior to 1.44.4 OATHAuth versions prior to 1.45.2
Description An issue in Wikimedia Foundation OATHAuth allows the exposure of sensitive information to an unauthorized actor.
Recommendations Update to version 1.43.7 or later. Update to version 1.44.4 or later. Update to version 1.45.2 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-34087

Affected Products

Oathauth
Mediawiki