THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jr78-w6w5-m8f8 (high) — Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

[GHSA] GHSA-jr78-w6w5-m8f8 (high) — Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

highgithub_advisoriesPublished 2026-09-18

GHSA-jr78-w6w5-m8f8 Severity: high CVE: None

Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

### Summary

The `api.php?action=smwtask` API module performs no authorization check. The equivalent maintenance interface in the web UI (`Special:SMWAdmin`) requires the `smw-admin` right, but the API module that backs se

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jr78-w6w5-m8f8