OVERVIEW CVE-2026-39937 is an improper removal of sensitive information vulnerability in the Wikimedia Foundation's MediaWiki CentralAuth Extension. The flaw allows sensitive data to be inadvertently stored or transferred in an unprotected state, creating a resource leak exposure. The vulnerability affects MediaWiki versions prior to 1.43, 1.44, and 1.45, with patches available on the master branch and corresponding release branches. SEVERITY While a CVSS score has not been assigned, the FAUCET Risk Score of 51.0/100 indicates moderate concern. The vulnerability relates to improper handling of sensitive information, which typically involves network-adjacent or local attack vectors with minimal complexity. The primary impact is confidentiality-related, as sensitive data exposure could compromise user information or system credentials stored within the CentralAuth extension. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog, has not achieved Hot List status, and carries an exceptionally low EPSS score of 0.00055, indicating minimal likelihood of exploitation. No public exploit code is known to be available, and community attention remains minimal at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| The Wikimedia Foundation | Mediawiki - CentralAuth Extension | >= 0, < 1.43CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.