Skip to content
Threat Feed
medium advisory

Authorization Bypass in MediaWiki RevisionDelete API

An authorization bypass vulnerability in MediaWiki's RevisionDelete API allows users with limited privileges to remove suppression bits, exposing protected content due to improper permission validation.

CVE-2026-102975 identifies a security vulnerability in MediaWiki where the action=revisiondelete API fails to properly validate the suppressrevision permission. When a request includes the suppress=no parameter, the system erroneously allows the operation if the caller possesses viewsuppressed and certain revision management rights (such as deleterevision or deletelogentry), even if they lack the elevated suppressrevision privilege.

This flaw allows an attacker to interact with the API to unsuppress sensitive revision content that should remain restricted, effectively exposing data intended for administrative suppression only. The vulnerability was reported by Marco Paciaroni and a public proof-of-concept (PoC) exploit script written in Python is available. Defenders should review MediaWiki permission configurations and ensure that the suppressrevision right is correctly restricted to authorized administrative roles. The issue is tracked via Phabricator ticket T435026.

Impact

The vulnerability results in an unauthorized exposure of suppressed or restricted wiki revision content. In production environments, this can lead to the accidental or malicious disclosure of private information, internal communications, or sensitive draft content that has been formally suppressed by administrators. The scope of impact is limited to wiki instances where granular permissions have been separated, allowing users to hold viewsuppressed without the corresponding suppressrevision authority.

Recommendation

  • Audit MediaWiki group permissions to ensure that the suppressrevision right is exclusively held by trusted administrative users.
  • Review MediaWiki installation logs and audit trails for unauthorized or unexpected action=revisiondelete API calls from accounts lacking the suppressrevision right.
  • Apply security patches or updates provided by the MediaWiki project addressing the flaw described in Phabricator ticket T435026.
  • Monitor webserver access logs for anomalous traffic patterns directed at the MediaWiki API, specifically targeting the action=revisiondelete endpoint.

Immediate actions

Audit MediaWiki roles and permissions for separation of viewsuppressed and suppressrevision rights

IT Operations 48h

Enrichment needed

  • Verify patched version for your specific MediaWiki deployment (IT Operations) Ensure the current environment is running a version that incorporates the fix for T435026.

Mitigations

Review MediaWiki audit logs for 'action=revisiondelete' activity from unauthorized accounts

immediate SOC

CVE-2026-102975