CVE-2026-39937 PUBLISHED

Global vanishing does not completely remove user email

Assigner: wikimedia-foundation
Reserved: 07.04.2026 Published: 07.04.2026 Updated: 08.04.2026

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects non release branches.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L
CVSS Score: 8.8

Product Status

Vendor The Wikimedia Foundation
Product Mediawiki - CentralAuth Extension
Versions Default: unaffected
  • Version 1.43.7 is unaffected
  • Version 1.44.4 is unaffected
  • Version 1.45.2 is unaffected

Credits

  • Urbanecm finder
  • kostajh remediation developer

References

Problem Types

  • CWE-212 Improper removal of sensitive information before storage or transfer CWE

Impacts

  • CAPEC-131 Resource Leak Exposure