Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-102971 — Sanitized report and loopback-only PoC for CVE-2026-102971, a MediaWiki REST revision response leaking hidden revision author user IDs. | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-102971
Vulnerability AnalysisExploitationInformation GatheringSecurity VirtualizationWeb SecurityPapers & Research
GitHubbombobombone/cve-2026-102971

CVE-2026-102971

Sanitized report and loopback-only PoC for CVE-2026-102971, a MediaWiki REST revision response leaking hidden revision author user IDs.

View Repository
3 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-102971: hidden revision author ID disclosure

Reporter: Marco Paciaroni (BomboBombone).

MediaWiki's RESTBase-compatible revision response could include the numeric user ID of an author whose name had been hidden. The response still set user_text to null and marked the author as hidden, but the exposed ID could be mapped to an account through the public user lookup API.

Impact and conditions

An unauthenticated caller could correlate a deliberately hidden revision author with the author's account. The disclosure requires a revision whose author field is hidden and a wiki exposing the core REST revision route.

Proof of concept

The script creates a disposable local page, hides the author of its new revision, compares the standard REST response with RESTBase compatibility enabled, checks that the local public user lookup resolves the ID, and cleans up the page and revision state.

Run it only against an isolated MediaWiki test instance on loopback. It refuses non-loopback hosts and requires an explicit confirmation flag. It prompts for the test account password instead of accepting it on the command line.

python poc.py --base http://127.0.0.1:8080 --username LocalAdmin --confirm-local-test

The account needs permission to edit a disposable page and hide its revision author (suppressrevision).

References

  • CVE record
  • Public Phabricator report and fix tracking
  • Blog write-up
Download Tool