MediaWiki’s Special:EmailUser form checked the EmailUserAuthorizeSend hook before sending a message. The action=emailuser API path did not run that hook, so a sender denied by an installed site or extension policy could still send through the API.
Technical details
The API called EmailUser::canSend() and then sendEmailUnsafe(). The web form called authorizeSend(), which runs EmailUserAuthorizeSend, before it reached the same send routine. Since sendEmailUnsafe() deliberately skips permission and policy checks, the API path missed the additional authorization decision.
This issue depends on configuration: a wiki is affected when an extension or local policy uses the hook to deny a sender. The stock core setup has no denying hook, so the omission alone does not create a restriction to bypass.
Reproduction
Configure EmailUserAuthorizeSend to deny a test sender. Submit a message through Special:EmailUser and through action=emailuser. The web form rejects the message; the API path sends it.
Impact
Where a site relies on this hook for email restrictions, a low-privilege authenticated account with the normal send-email permission could bypass that policy and send messages.
References
MediaWiki's `Special:EmailUser` form checked the `EmailUserAuthorizeSend` hook before sending a message. The `action=emailuser` API path did not run that hook, so a sender denied by an installed site or extension policy could still send through the API.
## Technical details
The API called `EmailUser::canSend()` and then `sendEmailUnsafe()`. The web form called `authorizeSend()`, which runs `EmailUserAuthorizeSend`, before it reached the same send routine. Since `sendEmailUnsafe()` deliberately skips permission and policy checks, the API path missed the additional authorization decision.
This issue depends on configuration: a wiki is affected when an extension or local policy uses the hook to deny a sender. The stock core setup has no denying hook, so the omission alone does not create a restriction to bypass.
## Reproduction
Configure `EmailUserAuthorizeSend` to deny a test sender. Submit a message through `Special:EmailUser` and through `action=emailuser`. The web form rejects the message; the API path sends it.
## Impact
Where a site relies on this hook for email restrictions, a low-privilege authenticated account with the normal send-email permission could bypass that policy and send messages.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-102973)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-102973)
- [Phabricator report and fix tracking](https://phabricator.wikimedia.org/T435022)
- [Research index](/about/)