Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-103442 — Local proof-of-concept and sanitized report for CVE-2026-103442, a PHP object injection in MediaWiki CentralAuth's merge-session handling that can lead to remote code execution. | Kitploit
Tools/GitHubGitHub/bombobombone/cve-2026-103442
Vulnerability AnalysisExploitationWeb Application ExploitationWeb Security
GitHubbombobombone/cve-2026-103442

CVE-2026-103442

Local proof-of-concept and sanitized report for CVE-2026-103442, a PHP object injection in MediaWiki CentralAuth's merge-session handling that can lead to remote code execution.

View Repository
3 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-103442: CentralAuth MergeAccount object injection

Reporter: Marco Paciaroni (BomboBombone).

CentralAuth accepted a browser-supplied merge-session key when decoding migration state. A user with the centralauth-merge right could substitute a key that produced a PHP object graph. The report's Guzzle FileCookieJar chain writes a file selected by the object; available gadget chains in the affected runtime can extend this object injection to remote code execution.

Proof of concept

Use a local MediaWiki installation with CentralAuth and a test account that has the merge right. Choose a unique marker path that does not already exist and is writable by the local PHP process:

python poc.py --base-url http://127.0.0.1:4016 --username TestMergeUser --password '<test-password>' --marker /tmp/cve-2026-103442-canary.txt

The script accepts loopback base URLs only. It creates and removes the marker file during the test.

References

  • CVE record
  • Public Phabricator report
  • CentralAuth fix on Gerrit
  • Blog write-up
Download Tool