Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-103440 — Report summary and local proof-of-concept script demonstrating CVE-2026-103440, a PageTriage API disclosure of suppressed reviewer usernames on MediaWiki. | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-103440
Vulnerability AnalysisExploitationInformation GatheringWeb SecurityAPI Security
GitHubbombobombone/cve-2026-103440

CVE-2026-103440

Report summary and local proof-of-concept script demonstrating CVE-2026-103440, a PageTriage API disclosure of suppressed reviewer usernames on MediaWiki.

View Repository
3 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-103440: PageTriage suppressed reviewer disclosure

Reporter: Marco Paciaroni (BomboBombone).

The public pagetriagelist API returned a reviewer's username and profile links even when the account was suppressed. An anonymous caller could retrieve the data if a PageTriage review record existed for that account.

Proof of concept

On a local wiki with PageTriage enabled, create a review record for a test account and suppress that account through the normal moderation workflow. Then query the API without logging in:

python poc.py --page-id <PAGE_ID> --api-url http://127.0.0.1/w/api.php

The request is read-only. Use only an authorized local test instance; the script accepts loopback API URLs only.

References

  • CVE record
  • Public Phabricator report
  • PageTriage fix on Gerrit
  • Blog write-up
Download Tool