TL;DR
Attackers are exploiting a MediaWiki RCE flaw tracked as CVE-2026-100382. This CVSS 10 unauthenticated RCE sits in the popular External Data extension. Details and a proof-of-concept are public, and hijacked wikis are already hosting web shells. Admins should upgrade to External Data 3.7 or disable it now.
- CVE: CVE-2026-100382
- CVSS: 10.0 (Critical · CVSSv4)
- Product: Wikimedia Foundation Mediawiki - ExternalData Extension
- Affected: < 3.7
- Impact: Unauthenticated remote code execution through wikitext in ExternalData
- Status: Exploited in the wild
- Patched in: 3.7
- EPSS: 0.9% (30-day)
- Action: Update to 3.7 now
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
The External Data RCE went public on September 25. Within a day, bots began hitting wikis that run the extension. Yaron Koren, the extension’s author, raised the alarm on the MediaWiki-l mailing list. He wrote that “someone started to aggressively go after wikis that have External Data installed, creating new files on those servers.”
A second admin, Marc Lajoie, confirmed his production wiki was hit. He logged 13 automated attack rounds on September 26. The attacker got a working web shell into the skins directory.
The bug report and its proof-of-concept now sit in public on Wikimedia Phabricator task T434961. As a result, anyone can repeat the attack.
How the Attack Works
Since version 3.0, External Data can run local programs on the server. However, it did not filter the commands passed in through a parser function. The CVE record says this works “without requiring authentication or any privileges, allowing for RCE.” The reporter reproduced it on the default extension setup. In short, this MediaWiki RCE needs no account at all. Any visitor who can reach the wiki can run commands as the web server user.
Lajoie’s logs show a clear pattern. First, the bot queries the wiki API to check for External Data. Next, it sends a burst of POST requests. Then it requests freshly written PHP files.
Affected Versions
All External Data releases before 3.7 are vulnerable. Lajoie ran Canasta 3.5.7 with MediaWiki 1.43.8 when the attack hit.
Patch and Mitigation Steps
Upgrade or Disable
Upgrade External Data to 3.7, or turn it off. Koren also plans to drop the local program feature for good.
Hunt for Compromise
- Search writable folders for new PHP files named Nx_*.php or NX_*.php.
- Check access logs since September 25 for extension probes followed by POST bursts to api.php.
- Block PHP execution in uploads at the web server level, not in .htaccess.
Rotate Secrets
If you ran an older version, treat LocalSettings.php as exposed. Change the database password, secret keys, and admin passwords. Also replace any API keys stored there. This MediaWiki RCE is already in active use, so every hour counts.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!