CVE-2026-100378 Overview
CVE-2026-100378 is a Missing Authorization vulnerability [CWE-862] in the Wikimedia Foundation MediaWiki Translate Extension. The flaw lets authenticated users access functionality that is not properly constrained by Access Control Lists (ACLs). Affected deployments include Translate Extension versions prior to 1.46.1, 1.45.5, and 1.43.10. Exploitation requires network access and low privileges, with no user interaction. Successful abuse enables limited integrity impact on wiki content managed by the extension.
Critical Impact
Authenticated users on affected MediaWiki installations can access Translate Extension functionality without proper authorization checks, potentially modifying translation data outside their intended permissions.
Affected Products
- MediaWiki Translate Extension versions before 1.46.1
- MediaWiki Translate Extension versions before 1.45.5
- MediaWiki Translate Extension versions before 1.43.10
Discovery Timeline
- 2026-09-25 - CVE CVE-2026-100378 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-100378
Vulnerability Analysis
The Translate Extension provides multilingual content management features for MediaWiki installations. The vulnerability stems from missing authorization checks on one or more extension entry points. An authenticated user can invoke functionality that should be restricted to higher-privileged roles. The impact is limited to integrity of translation-related data, with no confidentiality or availability consequences reported. See the Wikimedia Phabricator Task T433070 and the corresponding Wikimedia Gerrit Changeset for technical details on the fix.
Root Cause
The root cause is a Missing Authorization condition [CWE-862] within the Translate Extension codebase. Code paths that modify translation state do not verify whether the current user holds the required permissions before executing privileged operations. The patched versions introduce the appropriate ACL enforcement on those paths.
Attack Vector
Exploitation requires network access to the MediaWiki instance and a low-privileged authenticated account. No user interaction is required. The attacker sends crafted HTTP requests to Translate Extension endpoints to invoke functionality that should be gated by authorization checks. No public proof-of-concept exploit is listed in the referenced advisories.
No verified exploit code is available. Refer to the Wikimedia Gerrit
changeset I9b74c849b223f18955b42779f5ffbd1e051e415c for the authoritative
patch and the affected code paths within the Translate Extension.
Detection Methods for CVE-2026-100378
Indicators of Compromise
- Unexpected modifications to translation pages, message groups, or translation memory entries attributed to accounts without translator privileges.
- HTTP requests to Translate Extension API modules or special pages originating from low-privileged user sessions.
- Audit log entries showing successful privileged Translate actions performed by users outside the configured translator or administrator groups.
Detection Strategies
- Review MediaWiki action logs and the Translate Extension's own logs for authorization anomalies and unexpected message group changes.
- Correlate web server access logs with user permission groups to identify low-privileged accounts hitting Translate Extension endpoints.
- Hunt for repeated requests to translation-related api.php modules or Special:Translate actions from the same session.
Monitoring Recommendations
- Enable verbose logging on the MediaWiki Translate Extension and forward logs to a centralized SIEM or data lake.
- Alert on content changes made by newly created or infrequently used accounts.
- Baseline normal translator activity and flag deviations in volume, timing, or target namespaces.
How to Mitigate CVE-2026-100378
Immediate Actions Required
- Upgrade the Translate Extension to 1.46.1, 1.45.5, or 1.43.10 based on your MediaWiki branch.
- Audit recent Translate Extension activity for unauthorized changes performed by low-privileged accounts.
- Review MediaWiki user group assignments and remove unnecessary accounts from translator-adjacent groups.
Patch Information
The Wikimedia Foundation addressed the issue in Translate Extension releases 1.46.1, 1.45.5, and 1.43.10. The fix is tracked in Wikimedia Phabricator Task T433070 and implemented in the Wikimedia Gerrit Changeset. Administrators should apply the update that matches their MediaWiki core release.
Workarounds
- If immediate patching is not possible, restrict access to the Translate Extension by tightening MediaWiki user group permissions.
- Disable the Translate Extension temporarily on affected wikis where translation functionality is non-essential.
- Place the wiki behind an authenticating reverse proxy to limit anonymous and low-privileged exposure to Translate endpoints.
# Example: disable the Translate Extension in LocalSettings.php
# Comment out or remove the extension load line until the patch is applied
# wfLoadExtension( 'Translate' );
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.