MediaWiki’s action=revisiondelete API accepted suppress=no without requiring the suppressrevision right. A user with viewsuppressed and a type-specific revision-delete right could therefore remove suppression from an item despite lacking the permission to manage suppression.
Technical details
The API checked suppressrevision when setting suppression, but the branch that cleared the restricted bit did not make the same check. The HTML revision-delete form had an additional guard for users who could view suppressed items but could not manage their suppression.
The issue matters when permissions are split so that a group has viewsuppressed and deleterevision or deletelogentry, but not suppressrevision. The shared write path applies to revision-delete item types, including revisions and log entries.
Reproduction
With viewsuppressed and deleterevision but not suppressrevision, submit action=revisiondelete with suppress=no for a suppressed revision. The API makes the revision visible to anonymous users.
Impact
A user who could view suppressed material but lacked suppression-management authority could make that material visible to ordinary viewers. This can disclose content or metadata protected by the site’s suppression process. The issue depends on a permission configuration that separates viewing from suppression.
References
MediaWiki's `action=revisiondelete` API accepted `suppress=no` without requiring the `suppressrevision` right. A user with `viewsuppressed` and a type-specific revision-delete right could therefore remove suppression from an item despite lacking the permission to manage suppression.
## Technical details
The API checked `suppressrevision` when setting suppression, but the branch that cleared the restricted bit did not make the same check. The HTML revision-delete form had an additional guard for users who could view suppressed items but could not manage their suppression.
The issue matters when permissions are split so that a group has `viewsuppressed` and `deleterevision` or `deletelogentry`, but not `suppressrevision`. The shared write path applies to revision-delete item types, including revisions and log entries.
## Reproduction
With `viewsuppressed` and `deleterevision` but not `suppressrevision`, submit `action=revisiondelete` with `suppress=no` for a suppressed revision. The API makes the revision visible to anonymous users.
## Impact
A user who could view suppressed material but lacked suppression-management authority could make that material visible to ordinary viewers. This can disclose content or metadata protected by the site's suppression process. The issue depends on a permission configuration that separates viewing from suppression.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-102975)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-102975)
- [Phabricator report and fix tracking](https://phabricator.wikimedia.org/T435026)
- [Research index](/about/)