
Local proof-of-concept and sanitized report for CVE-2026-103442, a PHP object injection in MediaWiki CentralAuth's merge-session handling that can lead to remote code execution.
Reporter: Marco Paciaroni (BomboBombone).
CentralAuth accepted a browser-supplied merge-session key when decoding migration state. A user with the centralauth-merge right could substitute a key that produced a PHP object graph. The report's Guzzle FileCookieJar chain writes a file selected by the object; available gadget chains in the affected runtime can extend this object injection to remote code execution.
Use a local MediaWiki installation with CentralAuth and a test account that has the merge right. Choose a unique marker path that does not already exist and is writable by the local PHP process:
python poc.py --base-url http://127.0.0.1:4016 --username TestMergeUser --password '<test-password>' --marker /tmp/cve-2026-103442-canary.txt
The script accepts loopback base URLs only. It creates and removes the marker file during the test.