Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39937

31
FAUCET Score

OVERVIEW CVE-2026-39937 is an improper removal of sensitive information vulnerability in the Wikimedia Foundation's MediaWiki CentralAuth Extension. The flaw allows sensitive data to be inadvertently stored or transferred in an unprotected state, creating a resource leak exposure. The vulnerability affects MediaWiki versions prior to 1.43, 1.44, and 1.45, with patches available on the master branch and corresponding release branches. SEVERITY While a CVSS score has not been assigned, the FAUCET Risk Score of 51.0/100 indicates moderate concern. The vulnerability relates to improper handling of sensitive information, which typically involves network-adjacent or local attack vectors with minimal complexity. The primary impact is confidentiality-related, as sensitive data exposure could compromise user information or system credentials stored within the CentralAuth extension. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog, has not achieved Hot List status, and carries an exceptionally low EPSS score of 0.00055, indicating minimal likelihood of exploitation. No public exploit code is known to be available, and community attention remains minimal at this time.

Impacted Technologies

VendorProductVersion(s)CPE
The Wikimedia FoundationMediawiki - CentralAuth Extension
>= 0, < 1.43CNA affecteddefault affected

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 3rd percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

gerrit.wikimedia.org / r/q/I0b72427fa329aee85841a2cb23dec3058edce85e
phabricator.wikimedia.org / T418122