Unrated severityNVD Advisory· Published Jul 1, 2026· Updated Jul 1, 2026
Session fixation attacks on improperly configured OAuth 1.0a tools
CVE-2026-13707
Description
Session fixation vulnerability in Wikimedia Foundation OAuth.
This vulnerability is associated with program files src/Backend/MWOAuthServer.Php.
This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.
Affected products
1- Range: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.