BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.INFOMediaWiki / Information disclosure
30 Sept 2026 · 3 min
MediaWiki / Information disclosure · 30 Sept 2026

CVE-2026-102971: REST compatibility exposed hidden revision authors

MediaWiki RESTBase compatibility returned a hidden revision author's numeric user ID.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

MediaWiki’s REST revision endpoint redacted authors whose usernames had been hidden. The RESTBase compatibility response still included the same author’s raw numeric user_id, though user_text was null and the response marked the author as hidden.

Technical details

The compatibility header X-Restbase-Compat: true selects a legacy metadata format. That path read the author ID through a raw revision accessor while using a visibility-aware accessor for the author name. The inconsistent filtering exposed the identifier even though the response signaled that the identity was restricted.

The identifier could then be passed to the public list=users&ususerids=<id> API to recover the account name. This affected another person’s hidden revision and required no attacker account or special permission.

Reproduction

Request a revision with a hidden author using the normal REST response, then repeat with X-Restbase-Compat: true. In the affected response, user_text remains null and the userhidden restriction is present, but user_id contains a value that the public users query can map to an account.

Impact

The raw identifier let a requester map a revision marked hidden to the account that authored it. Revision content remained protected.

References

1541 UTF-8 BYTES .WEB.INFO · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.