Important Security Notice
More actions
Important Security Notice
Regarding a data security incident on September 26th
If you have received this post via email, you should refer to the live copy here, as it will be the most up to date.
On the 26th of September (2026), The Obby Wiki's server was accessed without authorization through a security vulnerability in ExternalData, a third-party MediaWiki extension we used widely throughout the wiki. The vulnerability (CVE-2026-100382) was made public on the 25th of September, and automated attacks against wikis running the extension began within 2 hours, from my estimate. I became aware of it shortly afterwards and have since removed the extension, cleaned the server, and rotated every credential.
The wiki's content was not changed, and I have found no sign that anyone gained persistent access to the server.
What happened
- Between roughly 00:14 and 06:00 UTC on the 26th of September, automated tools used the vulnerability to run commands on the wiki's primary user-facing web server.
- Their goal appears to have been harvesting server credentials (such as API keys, tokens, and other secrets) in order to reuse or sell elsewhere. I do not believe they were targeting the wiki specifically, or its users.
- One of those credentials, for the email service the wiki uses, was used to send a small number of emails. That credential has been revoked. If you received an email from the Obby Wiki unprompted during that time, please treat it with caution.
What may have been exposed
Because the attackers could reach the database, we have to assume the following data may have been viewed, although I have found no evidence that it was:
- Usernames and public profile information
- Email addresses, including those added to your account directly and those provided through Google or Discord sign-in. The Obby Wiki does not receive or retain the email address tied to your Roblox account, so that means most of you are safe. See the privacy policy for more information.
- IP addresses recorded for anti-spam and moderation purposes
What is not at risk:
- Roblox, Google and Discord accounts. Accounts you have linked to the Obby Wiki (including Roblox, Google, and Discord) are safe. The Obby Wiki only uses these to sign you in, and we never store access to your accounts on those services regardless.
- Wiki pages, edits, and files. After checking, nothing was changed.
What's been done
- Removed the vulnerable extension permanently (All external data and API requests will pass through Apiunto instead, see #16)
- Rebuilt the server software from clean copies and removed everything the attackers left behind
- Changed every password, key and secret the server uses
- Signed everyone out of the wiki (it is safe to sign in again)
- Added further protections so that a similar vulnerability in the future would be much harder to exploit
What you should do
- Be cautious of emails claiming to be from the Obby Wiki, particularly any sent around the 26th of September or any asking you to click a link or sign in. If in doubt, visit the wiki directly instead.
- If you use two-factor authentication on the Obby Wiki, please remove and re-add it in Special:Preferences.
- You will need to sign in again, if you haven't since this morning, since every session was terminated.
- Passwords are stored in a protected form and were unlikely to be taken, but if you sign in with a password and use the same password elsewhere, I recommend you change it on those sites, as a measure of caution.
Questions
If you have any questions or concerns, please contact me on Discord (@wlft, see the server below) or leave a message on my talk page. If you have issues messaging me on Discord, please ensure you are in the Discord server.
I will be posting more information on what happened later. This post was made out of an abundance of caution, because I cannot fully confirm what was stolen from the server and what was not, but I believe they were most likely targeting server credentials, rather than user data.
Thank you,
- Wolfite