Skip to main content
Vulnerability Database/CVE-2026-103051

CVE-2026-103051: MediaWiki CentralNotice XSS Vulnerability

CVE-2026-103051 is a stored XSS vulnerability in MediaWiki CentralNotice extension that allows attackers to inject malicious scripts. This article covers the technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-103051 Overview

CVE-2026-103051 is a stored cross-site scripting (XSS) vulnerability in the Wikimedia Foundation MediaWiki CentralNotice extension. The flaw stems from improper neutralization of user-supplied input during web page generation, classified as [CWE-79]. Attackers with the ability to submit content processed by CentralNotice can inject persistent JavaScript payloads that execute in the browsers of subsequent visitors. Because CentralNotice is used to display site-wide banners across Wikimedia projects, stored payloads can reach a broad audience of authenticated administrators and readers.

Critical Impact

Stored XSS in CentralNotice enables session hijacking, credential theft, and unauthorized actions performed in the context of viewing users, including administrators.

Affected Products

  • MediaWiki CentralNotice extension versions before 1.43.10
  • MediaWiki CentralNotice extension versions before 1.45.5
  • MediaWiki CentralNotice extension versions before 1.46.1

Discovery Timeline

  • 2026-09-30 - CVE-2026-103051 published to the National Vulnerability Database
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-103051

Vulnerability Analysis

The CentralNotice extension provides centrally managed banner notices displayed across MediaWiki wikis. The vulnerability arises when the extension renders attacker-controlled input into HTML output without sufficient contextual encoding or sanitization. When a privileged user creates or modifies a banner, unsanitized fields are stored and later served to end users, causing arbitrary script execution in the victim's browser session.

Stored XSS in a shared administrative surface such as CentralNotice carries elevated risk. Executed scripts run under the origin of the affected wiki, granting access to session cookies, CSRF tokens, and any MediaWiki API actions the victim is authorized to perform. Escalation paths include hijacking administrator sessions to modify content, install malicious gadgets, or pivot to other MediaWiki extensions.

Root Cause

The root cause is improper neutralization of input during web page generation [CWE-79]. Input intended to populate banner content or related metadata is emitted into HTML contexts without the encoding required for that context. Details of the specific fields and code paths are documented in the Wikimedia Gerrit Change Proposal and the Wikimedia Phabricator Task T432419.

Attack Vector

An attacker with permission to author or edit CentralNotice banners submits crafted input containing script content. The malicious payload persists in the CentralNotice storage layer. When any user loads a page that renders the affected banner, the payload executes in that user's browser. The exploit does not require the victim to interact beyond loading a page that displays the compromised notice.

No verified public exploit code is available. See the linked Gerrit and Phabricator references for the sanitization fix applied by the CentralNotice maintainers.

Detection Methods for CVE-2026-103051

Indicators of Compromise

  • CentralNotice banner records containing HTML tags such as <script>, <img onerror=...>, <svg>, or javascript: URIs in fields that should render only plain text or restricted markup.
  • MediaWiki logs showing banner edits followed by unexpected outbound requests from user browsers to attacker-controlled hosts.
  • Anomalous administrator account activity such as unexpected content changes or gadget installations shortly after users load pages with CentralNotice banners.

Detection Strategies

  • Audit the CentralNotice database tables for stored payloads by scanning banner body and translation fields for HTML event handlers and script constructs.
  • Deploy a Content Security Policy (CSP) with reporting to surface script executions from unexpected sources during banner rendering.
  • Correlate MediaWiki RecentChanges and CentralNotice logs with web server logs to identify banner edits that precede suspicious client-side behavior.

Monitoring Recommendations

  • Alert on modifications to CentralNotice banners by non-standard user accounts or from unusual IP addresses.
  • Monitor browser telemetry and CSP violation reports for script-src violations tied to page paths that render CentralNotice content.
  • Track failed and successful session token use for administrator accounts following exposure windows.

How to Mitigate CVE-2026-103051

Immediate Actions Required

  • Upgrade the CentralNotice extension to version 1.43.10, 1.45.5, or 1.46.1 as appropriate for your MediaWiki release branch.
  • Review all existing CentralNotice banners for injected script content and remove or sanitize affected entries.
  • Rotate session tokens and force re-authentication for privileged accounts that may have viewed compromised banners.

Patch Information

The Wikimedia Foundation addressed the issue in CentralNotice releases 1.43.10, 1.45.5, and 1.46.1. The upstream fix is tracked in the Wikimedia Gerrit Change Proposal and the Wikimedia Phabricator Task T432419.

Workarounds

  • Temporarily disable the CentralNotice extension in LocalSettings.php until the patched version is deployed.
  • Restrict the centralnotice-admin user right to a minimal set of trusted administrators to reduce the pool of users who can create banners.
  • Enforce a strict Content Security Policy that disallows inline scripts and untrusted script sources on wiki pages.
bash
# Disable the CentralNotice extension in LocalSettings.php
# Comment out or remove the following line until patched:
# wfLoadExtension( 'CentralNotice' );

# Then update via Composer or Git to a patched release
cd /var/www/mediawiki/extensions/CentralNotice
git fetch --tags
git checkout 1.46.1  # or 1.45.5 / 1.43.10 for your branch
php /var/www/mediawiki/maintenance/update.php

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.