A critical command injection flaw in the MediaWiki ExternalData extension is under active exploitation. Tracked as CVE-2026-100382, it carries a CVSS score of 10.0.
According to SecurityOnline and Ionix, the flaw was published on September 25, 2026. Within about a day, bots began probing wikis that run the extension. Public proof-of-concept code is available, and hijacked wikis are reported to be hosting web shells.
Why it matters: the bug is OS command injection (CWE-78). An attacker can run arbitrary commands with the privileges of the web server or PHP process. That means full compromise of the host, and a foothold for lateral movement. Wikis often sit on internal networks and hold internal documentation.
Technical detail: all versions of the ExternalData extension before 3.7 are affected. The flaw sits in the EDConnectorExe connector. It can be reached through wikitext, using a parser function that accepts a command argument. It can also be reached through the Lua/Scribunto API, where parameter names containing whitespace bypass validation. No authentication or user interaction is required, per the published analysis.
Mitigation: upgrade ExternalData to version 3.7 or later. The fix normalizes Lua parameter names and adds configuration to disable individual connectors and parsers. If you cannot patch now, disable the EDConnectorExe connector, restrict editing to trusted users, or disable the extension entirely.
Detection: review web server and PHP process activity for unexpected child processes. Hunt for newly created files in web-accessible directories, and audit recent page and Lua module edits that call the extension's program-data functions. Treat any exposed, unpatched wiki as potentially compromised.






























