BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.WEB.AUTHZMediaWiki / Authorization
30 Sept 2026 · 4 min
MediaWiki / Authorization · 30 Sept 2026

CVE-2026-102975: RevisionDelete API could remove suppression without the required right

The revision-delete API accepted suppress=no without checking suppressrevision.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

MediaWiki’s action=revisiondelete API accepted suppress=no without requiring the suppressrevision right. A user with viewsuppressed and a type-specific revision-delete right could therefore remove suppression from an item despite lacking the permission to manage suppression.

Technical details

The API checked suppressrevision when setting suppression, but the branch that cleared the restricted bit did not make the same check. The HTML revision-delete form had an additional guard for users who could view suppressed items but could not manage their suppression.

The issue matters when permissions are split so that a group has viewsuppressed and deleterevision or deletelogentry, but not suppressrevision. The shared write path applies to revision-delete item types, including revisions and log entries.

Reproduction

With viewsuppressed and deleterevision but not suppressrevision, submit action=revisiondelete with suppress=no for a suppressed revision. The API makes the revision visible to anonymous users.

Impact

A user who could view suppressed material but lacked suppression-management authority could make that material visible to ordinary viewers. This can disclose content or metadata protected by the site’s suppression process. The issue depends on a permission configuration that separates viewing from suppression.

References

1645 UTF-8 BYTES .WEB.AUTHZ · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.