CVE-2025-6926
Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X befo...
Affects 0 products across 3 vendors.
Software does not prove or insufficiently proves that the user is who they claim to be.
Show all 10
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows bypassing authentication, affecting specific versions of the extension.
BSID: BS-2025-GLOBAL-031914-H • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-6926?
What is the CVSS score for CVE-2025-6926?
Is CVE-2025-6926 actively exploited?
How do I remediate CVE-2025-6926?
What systems are affected by CVE-2025-6926?
| CVE ID | CVE-2025-6926 |
|---|---|
| BSID | BS-2025-GLOBAL-031914-H BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Published | 2025-07-03 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2.
Source: NIST NVD / MITRE CVE Database
An attacker can exploit this vulnerability to bypass authentication mechanisms in the CentralAuth Extension of Mediawiki, potentially gaining unauthorized access to user accounts and data.
Exploitation Likelihood: HIGH
| Vendor | Product | Fixed Version |
|---|---|---|
| Foundation | — | — |
| Mediawiki | — | — |
| Wikimedia | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | d7325fe8e9b255c0d5897aa08a19cf2a5c0d86c8f17d4cc40119878c7aaa525404e0bf8af80c043f6d6743168d8dc42735cfa3e6587dd8652e43962fc8faff59 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →