CVE-2025-11173
📋 TL;DR
This vulnerability in Wikimedia Foundation's OATHAuth extension allows attackers to bypass two-factor authentication (2FA) controls. It affects MediaWiki installations using OATHAuth for 2FA on user accounts. Users running affected versions without patches are vulnerable to authentication bypass.
💻 Affected Systems
- MediaWiki OATHAuth extension
⚠️ Risk & Real-World Impact
Worst Case
Complete bypass of two-factor authentication, allowing attackers to access protected accounts even with only password knowledge.
Likely Case
Targeted attackers could gain unauthorized access to administrator or privileged user accounts protected by 2FA.
If Mitigated
With proper network segmentation and monitoring, impact limited to isolated authentication system compromise.
🎯 Exploit Status
Requires some authentication knowledge; details not publicly disclosed
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: 1.39.14, 1.43.4, or 1.44.1
Vendor Advisory: https://phabricator.wikimedia.org/T401862
Restart Required: No
Instructions:
1. Update MediaWiki to patched version. 2. Update OATHAuth extension if separately installed. 3. Clear caches if needed.
🔧 Temporary Workarounds
Disable OATHAuth
allTemporarily disable two-factor authentication via OATHAuth extension
Remove or comment out wfLoadExtension('OATHAuth'); in LocalSettings.php
🧯 If You Can't Patch
- Implement network-level restrictions to limit access to Special:OATHManage
- Enable detailed logging for authentication events and monitor for suspicious patterns
🔍 How to Verify
Check if Vulnerable:
Check MediaWiki version and OATHAuth extension version against affected ranges
Check Version:
Check includes/DefaultSettings.php for $wgVersion or use Special:Version page
Verify Fix Applied:
Confirm MediaWiki version is 1.39.14, 1.43.4, 1.44.1 or higher
📡 Detection & Monitoring
Log Indicators:
- Unusual authentication patterns, multiple failed 2FA attempts followed by success
- Access to Special:OATHManage from unexpected locations
Network Indicators:
- Unusual traffic patterns to OATHAuth endpoints
SIEM Query:
source="mediawiki" AND (uri_path="/Special:OATHManage" OR message="OATHAuth")