Skip to main content
Vulnerability Database/CVE-2026-100240

CVE-2026-100240: MediaWiki TemplateSandbox Auth Bypass Flaw

CVE-2026-100240 is an authorization bypass flaw in MediaWiki TemplateSandbox Extension that enables unauthorized access to restricted functionality. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-100240 Overview

CVE-2026-100240 is a missing authorization vulnerability [CWE-862] in the Wikimedia Foundation MediaWiki TemplateSandbox extension. The extension fails to properly enforce access control on functionality that should be constrained by Access Control Lists (ACLs). Unauthorized users can reach protected functionality that ACL policies should restrict.

The issue affects TemplateSandbox versions prior to 1.46.1, 1.45.5, and 1.43.10. MediaWiki powers Wikipedia and thousands of collaborative wiki deployments, making the extension broadly deployed across public and private wikis.

Critical Impact

Missing authorization checks let unauthorized users invoke functionality that should require elevated permissions, weakening ACL-based content controls in affected MediaWiki installations.

Affected Products

  • Wikimedia Foundation MediaWiki TemplateSandbox extension versions before 1.46.1
  • Wikimedia Foundation MediaWiki TemplateSandbox extension versions before 1.45.5
  • Wikimedia Foundation MediaWiki TemplateSandbox extension versions before 1.43.10

Discovery Timeline

  • 2026-09-29 - CVE-2026-100240 published to the National Vulnerability Database
  • 2026-09-29 - Last updated in the NVD database

Technical Details for CVE-2026-100240

Vulnerability Analysis

The TemplateSandbox extension allows editors to preview template changes without saving them to production wiki pages. The extension exposes preview and rendering functionality that should honor the same permission model as normal page edits.

The vulnerability stems from missing authorization enforcement on one or more code paths within the extension. Requests that should be blocked by ACL checks proceed without validation. Attackers with lower privileges than intended can therefore invoke the affected functionality.

Because TemplateSandbox interacts with template rendering, weakened access control can influence how protected templates are previewed, evaluated, or exposed. Consult the Wikimedia Phabricator Task T407974 and the Wikimedia Gerrit Change Request for the authoritative fix scope.

Root Cause

The root cause is an omitted authorization check on an entry point exposed by the TemplateSandbox extension. The affected code path does not verify that the requesting user holds the permission required to invoke the operation. This aligns with the CWE-862 classification for missing authorization.

Attack Vector

A remote user with access to the wiki interface can reach the vulnerable endpoint. Because the check is missing rather than incorrectly implemented, no cryptographic bypass or crafted payload is required. The attacker sends a normal request to the exposed functionality that should have been gated by ACL policy.

No public proof-of-concept exploit is currently listed for this CVE. Refer to the linked Wikimedia references for technical specifics of the patched code paths.

Detection Methods for CVE-2026-100240

Indicators of Compromise

  • Unexpected access to TemplateSandbox preview or rendering endpoints by low-privilege accounts.
  • Web server access logs showing requests to Special:TemplateSandbox from accounts that lack template editing rights.
  • MediaWiki debug logs recording template previews of pages the requesting user cannot normally edit.

Detection Strategies

  • Inventory MediaWiki deployments and identify installations running TemplateSandbox versions below 1.46.1, 1.45.5, or 1.43.10.
  • Review MediaWiki audit and action logs for anomalous use of the TemplateSandbox special page by unprivileged users.
  • Correlate web application firewall logs with MediaWiki user roles to detect requests that bypass expected permission boundaries.

Monitoring Recommendations

  • Forward MediaWiki web server and application logs to a centralized SIEM or data lake for query-based hunting.
  • Alert on repeated requests to TemplateSandbox endpoints originating from anonymous or newly created accounts.
  • Track version metadata of installed MediaWiki extensions to detect unpatched hosts.

How to Mitigate CVE-2026-100240

Immediate Actions Required

  • Upgrade the TemplateSandbox extension to version 1.46.1, 1.45.5, or 1.43.10, matching your MediaWiki release branch.
  • Audit user and group permissions on affected wikis to confirm that ACL policies remain enforced after upgrade.
  • Review recent activity on TemplateSandbox endpoints for signs of unauthorized use prior to patching.

Patch Information

Wikimedia Foundation released fixed versions of the TemplateSandbox extension in 1.46.1, 1.45.5, and 1.43.10. The upstream patch is tracked in the Wikimedia Gerrit Change Request and the corresponding Wikimedia Phabricator Task T407974. Administrators should apply the patch on the release branch matching their MediaWiki core version.

Workarounds

  • Disable the TemplateSandbox extension in LocalSettings.php until the patched version can be deployed.
  • Restrict access to the Special:TemplateSandbox endpoint at the web server or reverse proxy layer to authenticated, trusted editors.
  • Require authentication for all edit-related endpoints and block anonymous access to template preview functionality.
bash
# Configuration example: disable the extension in LocalSettings.php
# Comment out or remove the extension load line, then restart the web server
# wfLoadExtension( 'TemplateSandbox' );

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.