CentralAuth’s Special:MergeAccount flow accepted a session key from the browser when decoding stored migration state. Because the relevant serialized plaintext could be derived from the password submitted to the preceding form, a user with access to the merge page could substitute a key that produced an attacker-chosen PHP object graph.
Technical details
The report’s PoC injects Guzzle’s FileCookieJar object. Its destructor writes to a path selected by the object, demonstrating that the request can create or overwrite a file writable by the PHP process. Available PHP gadget chains in affected deployments can extend the object injection to remote code execution. The issue requires CentralAuth and a user with the centralauth-merge right.
Reproduction
Use the PoC only with a local MediaWiki instance and a test account that has the merge right. It submits a merge dry-run request and writes a disposable marker file, then removes that marker. The script accepts loopback URLs only.
Impact
An attacker with the required merge permission could use PHP object injection to overwrite files writable by the PHP process and reach remote code execution through available gadget chains.
References
CentralAuth's `Special:MergeAccount` flow accepted a session key from the browser when decoding stored migration state. Because the relevant serialized plaintext could be derived from the password submitted to the preceding form, a user with access to the merge page could substitute a key that produced an attacker-chosen PHP object graph.
## Technical details
The report's PoC injects Guzzle's `FileCookieJar` object. Its destructor writes to a path selected by the object, demonstrating that the request can create or overwrite a file writable by the PHP process. Available PHP gadget chains in affected deployments can extend the object injection to remote code execution. The issue requires CentralAuth and a user with the `centralauth-merge` right.
## Reproduction
Use the PoC only with a local MediaWiki instance and a test account that has the merge right. It submits a merge dry-run request and writes a disposable marker file, then removes that marker. The script accepts loopback URLs only.
## Impact
An attacker with the required merge permission could use PHP object injection to overwrite files writable by the PHP process and reach remote code execution through available gadget chains.
## References
- [CVE record](https://www.cve.org/CVERecord?id=CVE-2026-103442)
- [Public report repository](https://github.com/BomboBombone/CVE-2026-103442)
- [Phabricator report](https://phabricator.wikimedia.org/T435624)
- [CentralAuth fix on Gerrit](https://gerrit.wikimedia.org/r/1346057)
- [Research index](/about/)