VYPR
High severity7.6NVD Advisory· Published Jul 1, 2026· Updated Jul 13, 2026

CVE-2026-13707

CVE-2026-13707

Description

Session fixation vulnerability in Wikimedia Foundation OAuth.

This vulnerability is associated with program files src/Backend/MWOAuthServer.Php.

This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.

Affected products

3
  • cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mediawiki:mediawiki:*:*:*:*:*:*:*:*range: >=1.43.0,<1.43.9
    • cpe:2.3:a:mediawiki:mediawiki:1.46.0:rc0:*:*:*:*:*:*
  • Range: 1.46.0, 1.45.4, 1.44.6, 1.43.9

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.