---
id: CVE-2026-13707
title: |-
  Session fixation vulnerability in Wikimedia Foundation OAuth.

   This vulnerability is associated with program files src/Backend/MWOAuthServer.Php.



  This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.
summary: |-
  Session fixation vulnerability in Wikimedia Foundation OAuth.

   This vulnerability is associated with program files src/Backend/MWOAuthServer.Php.



  This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L'
cwe:
  - CWE-384
vendor: mediawiki
product: mediawiki
affected:
  - 'mediawiki >= 1.43.0, < 1.43.9'
  - 'mediawiki >= 1.44.0, < 1.44.6'
  - 'mediawiki >= 1.45.0, < 1.45.4'
  - mediawiki = 1.46.0
patched:
  - mediawiki 1.45.4
published: '2026-07-01'
updated: '2026-07-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13707'
references:
  - url: 'https://phabricator.wikimedia.org/T428324'
    label: c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
tags:
  - nvd
epss: 0.00344
epssPercentile: 0.25103
ingestedAt: '2026-07-13T16:27:39.390Z'
---

## Overview

Session fixation vulnerability in Wikimedia Foundation OAuth.

 This vulnerability is associated with program files src/Backend/MWOAuthServer.Php.



This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.

## Affected

- `mediawiki >= 1.43.0, < 1.43.9`
- `mediawiki >= 1.44.0, < 1.44.6`
- `mediawiki >= 1.45.0, < 1.45.4`
- `mediawiki = 1.46.0`

## Remediation

Upgrade past the affected range:

- `mediawiki 1.45.4`
