MediaWiki’s REST revision endpoint redacted authors whose usernames had been hidden. The RESTBase compatibility response still included the same author’s raw numeric user_id, though user_text was null and the response marked the author as hidden.
Technical details
The compatibility header X-Restbase-Compat: true selects a legacy metadata format. That path read the author ID through a raw revision accessor while using a visibility-aware accessor for the author name. The inconsistent filtering exposed the identifier even though the response signaled that the identity was restricted.
The identifier could then be passed to the public list=users&ususerids=<id> API to recover the account name. This affected another person’s hidden revision and required no attacker account or special permission.
Reproduction
Request a revision with a hidden author using the normal REST response, then repeat with X-Restbase-Compat: true. In the affected response, user_text remains null and the userhidden restriction is present, but user_id contains a value that the public users query can map to an account.
Impact
The raw identifier let a requester map a revision marked hidden to the account that authored it. Revision content remained protected.
References
MediaWiki's REST revision endpoint redacted authors whose usernames had been hidden. The RESTBase compatibility response still included the same author's raw numeric `user_id`, though `user_text` was null and the response marked the author as hidden.
## Technical details
The compatibility header `X-Restbase-Compat: true` selects a legacy metadata format. That path read the author ID through a raw revision accessor while using a visibility-aware accessor for the author name. The inconsistent filtering exposed the identifier even though the response signaled that the identity was restricted.
The identifier could then be passed to the public `list=users&ususerids=<id>` API to recover the account name. This affected another person's hidden revision and required no attacker account or special permission.
## Reproduction
Request a revision with a hidden author using the normal REST response, then repeat with `X-Restbase-Compat: true`. In the affected response, `user_text` remains null and the `userhidden` restriction is present, but `user_id` contains a value that the public users query can map to an account.
## Impact
The raw identifier let a requester map a revision marked hidden to the account that authored it. Revision content remained protected.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-102971)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-102971)
- [Phabricator report and fix tracking](https://phabricator.wikimedia.org/T434521)
- [Research index](/about/)