1 OCT 2026 — A flaw in External Data, a widely used add-on for MediaWiki, the software behind Wikipedia and thousands of company and community wikis, was fixed quietly and then made public on 25 September. Within a day, automated attacks were planting web shells on wikis that had not yet updated.
The flaw, CVE-2026-100382, lets anyone who can reach a vulnerable wiki run commands on its server without logging in. It carries the maximum severity score of 10.
What the extension's author said
External Data has been able to run other software on the wiki's own server since version 3.0 in 2021. "This was probably a mistake," its author, Yaron Koren, wrote on the MediaWiki mailing list on 27 September.
The vulnerability "was already fixed a little while ago, but it was only publicized two days ago, and soon after that someone started to aggressively go after wikis that have External Data installed", he wrote. He told administrators to upgrade to version 3.7, which turns off running local applications by default, or to disable the extension. Koren said he plans to remove the feature entirely.
One administrator's account
Marc Lajoie, whose production wiki was hit, posted a detailed account in the same thread. He counted 13 automated attack rounds on 26 September between 01:42 and 23:20 UTC. In each round, the attacker asked the wiki which extensions it ran, sent a burst of requests, and checked whether newly written files could be reached.
The attacker wrote files in several folders. Most could not be run, but one copy in the wiki's skins folder could, giving a working web shell, a backdoor that lets the attacker run commands through the web server. Lajoie found no changes to user accounts or page content, but said anything the attacker could read, including the wiki's configuration file with its database password, had to be treated as exposed.
What administrators should do
The thread's advice, also summarised by SecurityOnline, is to upgrade External Data to 3.7 or disable it. Administrators who ran an older version after 25 September should look for recently created PHP files, especially files whose names start "Nx_" or "NX_", and check access logs for a query listing extensions followed by bursts of requests.
If a wiki was hit
If there are signs of compromise, they should change every secret in the wiki's settings file, including the database password and any API keys. Lajoie also advised setting the web server to refuse to run PHP in folders where files can be uploaded or written.
The gap between fix and disclosure
Wikis that updated promptly were safe, because the fix existed before the flaw was public. The attacks fell on those that had not updated, starting within a day of publication.
That pattern is common: once a flaw and its details are public, anyone can work out an attack, and automated scanners can reach every exposed site within hours. Extensions are particularly exposed because they are often installed once and updated rarely, by volunteers or small teams.