CVE-2025-11173

N/A Unknown

📋 TL;DR

This vulnerability in Wikimedia Foundation's OATHAuth extension allows attackers to bypass two-factor authentication (2FA) controls. It affects MediaWiki installations using OATHAuth for 2FA on user accounts. Users running affected versions without patches are vulnerable to authentication bypass.

💻 Affected Systems

Products:
  • MediaWiki OATHAuth extension
Versions: Before 1.39.14, 1.43.4, 1.44.1
Operating Systems: All
Default Config Vulnerable: ⚠️ Yes
Notes: Only affects installations with OATHAuth extension enabled for 2FA

⚠️ Risk & Real-World Impact

🔴

Worst Case

Complete bypass of two-factor authentication, allowing attackers to access protected accounts even with only password knowledge.

🟠

Likely Case

Targeted attackers could gain unauthorized access to administrator or privileged user accounts protected by 2FA.

🟢

If Mitigated

With proper network segmentation and monitoring, impact limited to isolated authentication system compromise.

🌐 Internet-Facing: HIGH
🏢 Internal Only: MEDIUM

🎯 Exploit Status

Public PoC: ✅ No
Weaponized: UNKNOWN
Unauthenticated Exploit: ✅ No
Complexity: MEDIUM

Requires some authentication knowledge; details not publicly disclosed

🛠️ Fix & Mitigation

✅ Official Fix

Patch Version: 1.39.14, 1.43.4, or 1.44.1

Vendor Advisory: https://phabricator.wikimedia.org/T401862

Restart Required: No

Instructions:

1. Update MediaWiki to patched version. 2. Update OATHAuth extension if separately installed. 3. Clear caches if needed.

🔧 Temporary Workarounds

Disable OATHAuth

all

Temporarily disable two-factor authentication via OATHAuth extension

Remove or comment out wfLoadExtension('OATHAuth'); in LocalSettings.php

🧯 If You Can't Patch

  • Implement network-level restrictions to limit access to Special:OATHManage
  • Enable detailed logging for authentication events and monitor for suspicious patterns

🔍 How to Verify

Check if Vulnerable:

Check MediaWiki version and OATHAuth extension version against affected ranges

Check Version:

Check includes/DefaultSettings.php for $wgVersion or use Special:Version page

Verify Fix Applied:

Confirm MediaWiki version is 1.39.14, 1.43.4, 1.44.1 or higher

📡 Detection & Monitoring

Log Indicators:

  • Unusual authentication patterns, multiple failed 2FA attempts followed by success
  • Access to Special:OATHManage from unexpected locations

Network Indicators:

  • Unusual traffic patterns to OATHAuth endpoints

SIEM Query:

source="mediawiki" AND (uri_path="/Special:OATHManage" OR message="OATHAuth")

🔗 References

📤 Share This