
Sanitized report and local proof-of-concept script demonstrating the MediaWiki action=emailuser API EmailUserAuthorizeSend hook bypass (CVE-2026-102973).
Reporter: Marco Paciaroni (BomboBombone).
MediaWiki's action=emailuser API path did not invoke the EmailUserAuthorizeSend hook. When an extension or site policy used that hook to deny a sender, the web form enforced the denial while the API path could still send the message.
This is configuration-dependent. It affects a wiki only when a local policy or extension uses EmailUserAuthorizeSend as an authorization control. The stock core configuration does not provide a denying hook by itself. An affected account also needs the normal send-email permission.
Configure an isolated local test wiki with a temporary hook that denies a disposable sender, and configure MediaWiki mail to deliver only to a local SMTP sink such as Mailpit. Create a disposable recipient account for that sink. The script compares the denied web form with the API request and reports whether the API skipped the policy hook.
The script refuses non-loopback wiki URLs, requires an explicit local-SMTP confirmation flag and typed confirmation, and prompts for the sender password. Do not use a wiki configured to send mail externally.
python poc.py --base http://127.0.0.1:8080 --username PolicyTestSender --target CVE102973TestRecipient --confirm-local-smtp
The hook's denial message must contain email-policy-denied (the default marker). The sender needs the normal sendemail right, and the recipient must use the local sink address.