Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4249-1 | mediawiki security update |
Debian DSA |
DSA-5957-1 | mediawiki security update |
EUVD |
EUVD-2025-19884 | Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 03 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 03 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | |
| Title | Security Authentication Bypass in CentralAuth | |
| Weaknesses | CWE-287 | |
| References |
|
Status: PUBLISHED
Assigner: wikimedia-foundation
Published:
Updated: 2025-11-03T20:07:17.094Z
Reserved: 2025-06-30T14:28:12.256Z
Link: CVE-2025-6926
Updated: 2025-11-03T20:07:17.094Z
Status : Deferred
Published: 2025-07-03T17:15:41.100
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-6926
No data.
OpenCVE Enrichment
Updated: 2025-07-13T22:31:32Z
Debian DLA
Debian DSA
EUVD