Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-102973 — Sanitized report and local proof-of-concept script demonstrating the MediaWiki action=emailuser API EmailUserAuthorizeSend hook bypass (CVE-2026-102973). | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-102973
Authentication & AuthorizationVulnerability AnalysisExploitationWeb SecurityPenetration TestingAPI Security
GitHubbombobombone/cve-2026-102973

CVE-2026-102973

Sanitized report and local proof-of-concept script demonstrating the MediaWiki action=emailuser API EmailUserAuthorizeSend hook bypass (CVE-2026-102973).

View Repository
3 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-102973: API email authorization hook bypass

Reporter: Marco Paciaroni (BomboBombone).

MediaWiki's action=emailuser API path did not invoke the EmailUserAuthorizeSend hook. When an extension or site policy used that hook to deny a sender, the web form enforced the denial while the API path could still send the message.

Impact and conditions

This is configuration-dependent. It affects a wiki only when a local policy or extension uses EmailUserAuthorizeSend as an authorization control. The stock core configuration does not provide a denying hook by itself. An affected account also needs the normal send-email permission.

Proof of concept

Configure an isolated local test wiki with a temporary hook that denies a disposable sender, and configure MediaWiki mail to deliver only to a local SMTP sink such as Mailpit. Create a disposable recipient account for that sink. The script compares the denied web form with the API request and reports whether the API skipped the policy hook.

The script refuses non-loopback wiki URLs, requires an explicit local-SMTP confirmation flag and typed confirmation, and prompts for the sender password. Do not use a wiki configured to send mail externally.

python poc.py --base http://127.0.0.1:8080 --username PolicyTestSender --target CVE102973TestRecipient --confirm-local-smtp

The hook's denial message must contain email-policy-denied (the default marker). The sender needs the normal sendemail right, and the recipient must use the local sink address.

References

  • CVE record
  • Public Phabricator report and fix tracking
  • Blog write-up
Download Tool