BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.AUTHZMediaWiki / Authorization
30 Sept 2026 · 3 min
MediaWiki / Authorization · 30 Sept 2026

CVE-2026-102973: API email sending skipped an authorization hook

MediaWiki's email API omitted the EmailUserAuthorizeSend policy hook used by the web form.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

MediaWiki’s Special:EmailUser form checked the EmailUserAuthorizeSend hook before sending a message. The action=emailuser API path did not run that hook, so a sender denied by an installed site or extension policy could still send through the API.

Technical details

The API called EmailUser::canSend() and then sendEmailUnsafe(). The web form called authorizeSend(), which runs EmailUserAuthorizeSend, before it reached the same send routine. Since sendEmailUnsafe() deliberately skips permission and policy checks, the API path missed the additional authorization decision.

This issue depends on configuration: a wiki is affected when an extension or local policy uses the hook to deny a sender. The stock core setup has no denying hook, so the omission alone does not create a restriction to bypass.

Reproduction

Configure EmailUserAuthorizeSend to deny a test sender. Submit a message through Special:EmailUser and through action=emailuser. The web form rejects the message; the API path sends it.

Impact

Where a site relies on this hook for email restrictions, a low-privilege authenticated account with the normal send-email permission could bypass that policy and send messages.

References

1492 UTF-8 BYTES .WEB.AUTHZ · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.