BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.DATAMediaWiki / Information Disclosure
30 Sept 2026 · 3 min
MediaWiki / Information Disclosure · 30 Sept 2026

CVE-2026-103440: PageTriage exposed suppressed reviewer usernames

The public pagetriagelist API returned reviewer names and profile links even when the reviewer was suppressed.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

PageTriage’s public pagetriagelist API could reveal the identity of a suppressed user recorded as a page reviewer. The API redacted a suppressed page creator, but still returned reviewer names and user-page links.

Technical details

An anonymous request for a page with a PageTriage review record could return the suppressed reviewer’s name, user page, talk page, and contributions links. The lookup required no authentication or action from the affected user. Creating the review record and suppressing the username requires an authorized moderator.

Reproduction

On a local wiki with PageTriage enabled, create a review record, suppress the reviewer’s username, then request that page through action=pagetriagelist without logging in. The PoC makes a read-only request to a loopback API and prints the response.

Impact

Anonymous visitors could recover account identities that the wiki’s suppression process was intended to hide, using public review metadata.

References

1299 UTF-8 BYTES .DATA · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.