BomboBombone.exe
ARCHITECTURE:x86-64
BACK
.DATAMediaWiki / Object Injection
30 Sept 2026 · 4 min
MediaWiki / Object Injection · 30 Sept 2026

CVE-2026-103442: CentralAuth object injection and RCE

A caller-controlled merge-session key enabled PHP object injection, file overwrite, and remote code execution gadget chains.

POST VIEWTEXT / UTF-8
ADDRESS MARKDOWN BYTES

CentralAuth’s Special:MergeAccount flow accepted a session key from the browser when decoding stored migration state. Because the relevant serialized plaintext could be derived from the password submitted to the preceding form, a user with access to the merge page could substitute a key that produced an attacker-chosen PHP object graph.

Technical details

The report’s PoC injects Guzzle’s FileCookieJar object. Its destructor writes to a path selected by the object, demonstrating that the request can create or overwrite a file writable by the PHP process. Available PHP gadget chains in affected deployments can extend the object injection to remote code execution. The issue requires CentralAuth and a user with the centralauth-merge right.

Reproduction

Use the PoC only with a local MediaWiki instance and a test account that has the merge right. It submits a merge dry-run request and writes a disposable marker file, then removes that marker. The script accepts loopback URLs only.

Impact

An attacker with the required merge permission could use PHP object injection to overwrite files writable by the PHP process and reach remote code execution through available gadget chains.

References

1530 UTF-8 BYTES .DATA · ADDRESSES ARE UTF-8 BYTE OFFSETS

Resize column

Choose a width with the slider or the narrower and wider buttons.