A critical unauthenticated remote code execution vulnerability (CVE-2026-100382 with a CVSS score of 10.0) exists in the External Data extension of Wikimedia Foundation Mediawiki, allowing attackers to run local programs on the server without requiring authentication or any privileges, enabling RCE through wikitext in ExternalData and impacting admins who should upgrade to version 3.7 or disable it now as details and a proof-of-concept are public and hijacked wikis are already hosting web shells, with all External Data releases before 3.7 being vulnerable; the flaw type is an unauthenticated RCE vulnerability, attack vector is through wikitext in ExternalData, and business impact includes potential data breaches, unauthorized access to sensitive information, and disruption of services; admins should take immediate action to mitigate this vulnerability by upgrading or disabling the extension.
We recommend you to update External Data to version 3.7 or disable it now.[/subscribe_to_unlock_form]
A critical unauthenticated remote code execution vulnerability (CVE-2026-100382 with a CVSS score of 10.0) exists in the External Data extension of Wikimedia Foundation Mediawiki, allowing attackers to run local programs on the server without requiring authentication or any privileges, enabling RCE through wikitext in ExternalData and impacting admins who should upgrade to version 3.7 or disable it now as details and a proof-of-concept are public and hijacked wikis are already hosting web shells, with all External Data releases before 3.7 being vulnerable; the flaw type is an unauthenticated RCE vulnerability, attack vector is through wikitext in ExternalData, and business impact includes potential data breaches, unauthorized access to sensitive information, and disruption of services; admins should take immediate action to mitigate this vulnerability by upgrading or disabling the extension.
We recommend you to update External Data to version 3.7 or disable it now.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]