BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.DATAMediaWiki / Deserialization
30 Sept 2026 · 4 min
MediaWiki / Deserialization · 30 Sept 2026

CVE-2026-103441: Wikibase deserialization enabled file deletion and RCE

Unauthenticated PHP object injection through Wikibase parsing can reach file deletion and remote code execution gadget chains.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

MediaWiki’s public action=parse API accepted PHP-serialized input for Wikibase entities. Wikibase deserialized the request without disabling object construction. With Widgets loaded, a crafted Smarty object graph reached a destructor that called unlink() with a request-controlled lock path.

Technical details

The demonstrated setup required Wikibase Repository and Widgets. An unauthenticated request could make the PHP process delete a file it was allowed to unlink. Available PHP gadget chains in the affected Wikimedia runtime can extend this object injection path to remote code execution. The PoC uses a fixed disposable marker path in a local test environment.

Reproduction

In a local MediaWiki instance with the affected extensions, create the marker file as a path the PHP service can remove, then run the loopback-only PoC. It submits the serialized entity through action=parse and checks whether the marker was removed.

Impact

An unauthenticated caller could reach PHP object injection in the MediaWiki process. The public PoC demonstrates deletion of a file accessible to that process; available gadget chains make remote code execution a further impact in affected deployments.

References

1531 UTF-8 BYTES .DATA · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.