<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Wikimedia Foundation - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/wikimedia-foundation/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:32:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/wikimedia-foundation/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>MediaWiki RESTBase Information Disclosure Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-mediawiki-info-disclosure/</link><pubDate>Wed, 30 Sep 2026 16:32:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mediawiki-info-disclosure/</guid><description>MediaWiki is susceptible to an information disclosure flaw where the RESTBase-compatible API exposes the numeric user ID of hidden revision authors, allowing unauthenticated attackers to map IDs to usernames.</description><content:encoded><![CDATA[<p>A vulnerability in MediaWiki's RESTBase-compatible revision response allows for the unauthenticated disclosure of numeric user IDs associated with hidden revision authors. While the <code>user_text</code> field is correctly set to <code>null</code> and the author is marked as hidden in the API response, the underlying numeric user ID remains exposed. This ID can be cross-referenced against the public MediaWiki user lookup API to de-anonymize the author of a hidden revision. The vulnerability affects instances where the core REST revision route is exposed and the RESTBase-compatible response format is utilized. The issue was disclosed by researcher Marco Paciaroni (BomboBombone) and tracked in the MediaWiki Phabricator system under task T434521. Defenders should assess exposure of their REST API endpoints and verify patch status for affected MediaWiki versions.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows an unauthenticated actor to bypass privacy controls intended to hide revision history. By mapping the leaked numeric user ID to a public username, attackers can de-anonymize contributors who have requested privacy via the 'suppressrevision' feature. This impacts organizations relying on MediaWiki for internal or public documentation where author attribution requires strict privacy controls.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web access logs for unusual patterns of sequential requests to MediaWiki REST revision endpoints and subsequent requests to user lookup APIs.</li>
<li>Audit MediaWiki configurations to restrict access to the REST revision route if it is not required for public-facing operations.</li>
<li>Apply the vendor-provided patch associated with Phabricator task T434521 immediately.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>information-disclosure</category><category>mediawiki</category><category>vulnerability</category></item></channel></rss>