Cybersecurity 4 min read

A Wiki Add-On Was Fixed Quietly. Attacks Began a Day After the Flaw Was Made Public.

CVE-2026-100382 in MediaWiki's External Data extension lets anyone run commands on a wiki's server. Bots planted web shells on unpatched wikis from 26 September.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 1 Oct 2026, 4:30 PM (SGT)
Share:
Blue network cables plugged into a server rack Blue network cables plugged into a server rack Photo by Brett Sayles on Pexels
Advertisement

1 OCT 2026 — A flaw in External Data, a widely used add-on for MediaWiki, the software behind Wikipedia and thousands of company and community wikis, was fixed quietly and then made public on 25 September. Within a day, automated attacks were planting web shells on wikis that had not yet updated.

The flaw, CVE-2026-100382, lets anyone who can reach a vulnerable wiki run commands on its server without logging in. It carries the maximum severity score of 10.

What the extension's author said

External Data has been able to run other software on the wiki's own server since version 3.0 in 2021. "This was probably a mistake," its author, Yaron Koren, wrote on the MediaWiki mailing list on 27 September.

The vulnerability "was already fixed a little while ago, but it was only publicized two days ago, and soon after that someone started to aggressively go after wikis that have External Data installed", he wrote. He told administrators to upgrade to version 3.7, which turns off running local applications by default, or to disable the extension. Koren said he plans to remove the feature entirely.

10.0Severity score, the maximum
25 SeptFlaw made public
13Automated attack rounds on one wiki on 26 September
3.7Version that fixes it; older versions are vulnerable

One administrator's account

Marc Lajoie, whose production wiki was hit, posted a detailed account in the same thread. He counted 13 automated attack rounds on 26 September between 01:42 and 23:20 UTC. In each round, the attacker asked the wiki which extensions it ran, sent a burst of requests, and checked whether newly written files could be reached.

The attacker wrote files in several folders. Most could not be run, but one copy in the wiki's skins folder could, giving a working web shell, a backdoor that lets the attacker run commands through the web server. Lajoie found no changes to user accounts or page content, but said anything the attacker could read, including the wiki's configuration file with its database password, had to be treated as exposed.

Advertisement

What administrators should do

The thread's advice, also summarised by SecurityOnline, is to upgrade External Data to 3.7 or disable it. Administrators who ran an older version after 25 September should look for recently created PHP files, especially files whose names start "Nx_" or "NX_", and check access logs for a query listing extensions followed by bursts of requests.

If a wiki was hit

If there are signs of compromise, they should change every secret in the wiki's settings file, including the database password and any API keys. Lajoie also advised setting the web server to refuse to run PHP in folders where files can be uploaded or written.

The gap between fix and disclosure

Wikis that updated promptly were safe, because the fix existed before the flaw was public. The attacks fell on those that had not updated, starting within a day of publication.

That pattern is common: once a flaw and its details are public, anyone can work out an attack, and automated scanners can reach every exposed site within hours. Extensions are particularly exposed because they are often installed once and updated rarely, by volunteers or small teams.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement