Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-102975 — Sanitized report and local proof-of-concept script for CVE-2026-102975, a MediaWiki RevisionDelete API authorization bypass allowing suppression removal without suppressrevision. | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-102975
Authentication & AuthorizationVulnerability AnalysisExploitationWeb SecurityPenetration TestingPapers & Research
GitHubbombobombone/cve-2026-102975

CVE-2026-102975

Sanitized report and local proof-of-concept script for CVE-2026-102975, a MediaWiki RevisionDelete API authorization bypass allowing suppression removal without suppressrevision.

View Repository
3 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-102975: RevisionDelete API unsuppression authorization bypass

Reporter: Marco Paciaroni (BomboBombone).

MediaWiki's action=revisiondelete accepted suppress=no without checking suppressrevision. A caller with viewsuppressed and a type-specific management right could remove the restricted bit even without the right to manage suppression.

Impact and conditions

A permission setup that grants viewsuppressed and deleterevision or deletelogentry without suppressrevision allowed the caller to expose material protected by the suppression workflow. This cross-user authorization issue depends on those rights being separated.

Proof of concept

Prepare a disposable revision containing only a harmless canary string and suppress its content on an isolated local wiki. Create a test account with viewsuppressed and deleterevision, but not suppressrevision. The script sends the vulnerable API request, checks whether an anonymous request can see the canary, and uses a separate test administrator to restore suppression.

The script refuses non-loopback wiki URLs, checks both accounts' rights, prompts for both passwords, and requires typed confirmation before changing the test revision's visibility. Use only a disposable local fixture.

python poc.py --base http://127.0.0.1:8080 --username ViewOnlyEditor --restore-username LocalAdmin --page-title CVE102975DisposablePage --revision-id 123 --confirm-test-fixture

The revision ID and page title must refer to the suppressed canary fixture. The restoration account needs suppressrevision.

References

  • CVE record
  • Public Phabricator report and fix tracking
  • Blog write-up
Download Tool