CVE-2026-103441
HighPublished
Unauthenticated arbitrary file deletion through Wikibase serialized entity parsing
- Published
- Sep 30, 2026
- Updated
- Sep 30, 2026
- Assigning CNA
- wikimedia-foundation
- Evidence observed
- Oct 3, 2026
Primary CVSS
7.2/ 10High
nvd · CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:I/V:C/RE:M/U:RedSummary
Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.
Sources
Local proof-of-concept and sanitized report for CVE-2026-103441, a PHP object-injection flaw in the MediaWiki action=parse API that can reach RCE via gadget chains.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.