CVE-2026-103047 Overview
CVE-2026-103047 is a stored cross-site scripting (XSS) vulnerability in the Wikimedia Foundation MediaWiki CentralAuth extension. The extension manages unified login across MediaWiki wikis. Improper neutralization of user-supplied input during web page generation allows attackers to store malicious script content that executes in the browsers of subsequent visitors [CWE-79].
The issue affects CentralAuth versions before 1.46.1, 1.45.5, and 1.43.10. Exploitation can lead to session hijacking, privilege escalation against administrators, and unauthorized actions performed under the identity of authenticated users.
Critical Impact
Stored XSS in CentralAuth executes attacker-controlled JavaScript in the context of any user viewing the affected page, including wiki administrators with elevated privileges.
Affected Products
- MediaWiki CentralAuth extension versions before 1.43.10
- MediaWiki CentralAuth extension versions before 1.45.5
- MediaWiki CentralAuth extension versions before 1.46.1
Discovery Timeline
- 2026-09-29 - CVE-2026-103047 published to NVD
- 2026-09-29 - Last updated in NVD database
Technical Details for CVE-2026-103047
Vulnerability Analysis
The CentralAuth extension provides global user account management across MediaWiki installations. The vulnerability arises when user-controlled input reaches HTML output rendering paths without adequate encoding or sanitization. An attacker persists a crafted payload through an input field handled by the extension. When another user loads the affected view, the browser parses the payload as executable JavaScript rather than inert text.
Stored XSS is more damaging than reflected XSS because delivery does not require social engineering. Any user who visits the affected page receives the payload. In a wiki environment with global accounts, a single injected payload can propagate impact across multiple wikis served by the same CentralAuth deployment.
Successful exploitation enables session token theft, forced administrative actions through CSRF-style script requests, defacement, and pivoting to internal wiki tooling. Wiki administrators are high-value targets since compromise of their session yields access to user management and content controls.
Root Cause
The root cause is missing or insufficient output encoding on data that traverses the CentralAuth request handling pipeline. Fields intended for display in HTML contexts must be encoded with context-aware escaping. The vulnerable versions failed to apply sufficient sanitization before rendering, permitting HTML and script tags to reach the DOM intact.
Attack Vector
An authenticated attacker submits crafted input containing JavaScript through a CentralAuth-managed field. The server stores the payload in the wiki backend. When a victim, typically a moderator or administrator, opens the corresponding view, the browser executes the injected script under the wiki's origin. See the Wikimedia Gerrit Code Review and Wikimedia Task Analysis T244682 for the patch and technical context.
Detection Methods for CVE-2026-103047
Indicators of Compromise
- Unexpected <script>, <img onerror=>, or event-handler attributes stored in CentralAuth-managed database rows.
- HTTP responses from CentralAuth endpoints containing HTML tags in fields that should render as plain text.
- Browser console errors or unexpected outbound requests to attacker-controlled domains when viewing CentralAuth pages.
Detection Strategies
- Audit CentralAuth database tables for stored input containing HTML control characters, script tags, or JavaScript URI schemes.
- Deploy a Content Security Policy (CSP) with reporting enabled and monitor violation reports for inline script attempts on CentralAuth routes.
- Review web server access logs for unusual POST requests to CentralAuth endpoints from newly created or low-reputation accounts.
Monitoring Recommendations
- Enable MediaWiki audit logging for account and preferences changes handled by CentralAuth.
- Alert on administrator session activity originating from unusual IP addresses or user agents shortly after CentralAuth page views.
- Track outbound requests from browsers of privileged users toward domains not on an approved allowlist.
How to Mitigate CVE-2026-103047
Immediate Actions Required
- Upgrade the CentralAuth extension to version 1.46.1, 1.45.5, or 1.43.10 depending on the deployed MediaWiki branch.
- Rotate session tokens and force reauthentication for administrator accounts.
- Review recent edits and preference changes for suspicious payloads and remove them.
Patch Information
The fix is available in the Wikimedia code review at Wikimedia Gerrit Code Review. Additional context and remediation tracking are documented in Wikimedia Task Analysis T244682. Apply the corresponding maintenance release for your MediaWiki branch: 1.43.10, 1.45.5, or 1.46.1.
Workarounds
- Disable the CentralAuth extension until the patch is applied if global login is not required.
- Enforce a strict Content Security Policy that blocks inline scripts and restricts script sources to trusted origins.
- Restrict account creation and limit CentralAuth-managed input fields to trusted user groups pending remediation.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.