securityonline.info 1 Oct 2026, 03:29 UTC

MediaWiki Extension Flaw Lets Attackers Deploy Web Shells

MediaWiki Extension Flaw Lets Attackers Deploy Web Shells
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

MEDIAWIKI is actively being exploited for a critical unauthenticated remote code execution flaw in the External Data extension, tracked as CVE-2026-100382. The bug allows an attacker to run arbitrary commands on the web server via wikitext, without authentication. Public PoC code and reports indicate attackers are scanning wikis running External Data and deploying web shells after delivering malicious PHP files.

In the wild activity was corroborated by multiple admins, including a production wiki owner who confirmed 13 automated attack rounds on 26 September, with the attacker obtaining a working web shell in the skins directory. The issue is being tracked as exploited in the wild, and the public discussion and task on Wikimedia Phabricator (T434961) make it clear the attack pattern can be repeated by anyone.

Affected versions are all External Data releases prior to 3.7; one demonstrator ran External Data 3.5.7 with MediaWiki 1.43.8 when attacked. The CVE description notes that External Data can execute local server programs and did not properly filter commands passed through a parser function, enabling RCE for any visitor who can reach the wiki.

Mitigation steps include upgrading External Data to 3.7 or disabling the extension entirely, as well as practical checks for compromise such as looking for newly written PHP files named Nx_*.php in writable folders and unusual POST bursts to api[.]php following API probing. Organisations should rotate secrets in LocalSettings[.]php and related keys, and block PHP execution in uploads at the web server level.

View full article

Article by CyberSIXT