
Sanitized report and local proof-of-concept script for CVE-2026-102975, a MediaWiki RevisionDelete API authorization bypass allowing suppression removal without suppressrevision.
Reporter: Marco Paciaroni (BomboBombone).
MediaWiki's action=revisiondelete accepted suppress=no without checking suppressrevision. A caller with viewsuppressed and a type-specific management right could remove the restricted bit even without the right to manage suppression.
A permission setup that grants viewsuppressed and deleterevision or deletelogentry without suppressrevision allowed the caller to expose material protected by the suppression workflow. This cross-user authorization issue depends on those rights being separated.
Prepare a disposable revision containing only a harmless canary string and suppress its content on an isolated local wiki. Create a test account with viewsuppressed and deleterevision, but not suppressrevision. The script sends the vulnerable API request, checks whether an anonymous request can see the canary, and uses a separate test administrator to restore suppression.
The script refuses non-loopback wiki URLs, checks both accounts' rights, prompts for both passwords, and requires typed confirmation before changing the test revision's visibility. Use only a disposable local fixture.
python poc.py --base http://127.0.0.1:8080 --username ViewOnlyEditor --restore-username LocalAdmin --page-title CVE102975DisposablePage --revision-id 123 --confirm-test-fixture
The revision ID and page title must refer to the suppressed canary fixture. The restoration account needs suppressrevision.