CVE-2025-32696: "reupload-own" restriction can be bypassed by reverting file
Improper Preservation of Permissions vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/actions/RevertAction.Php, includes/api/ApiFileRevert.Php.
This issue affects MediaWiki: before 1.39.12, 1.42.6, 1.43.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32696?
The severity of CVE-2025-32696 is considered to be significant due to its impact on permissions in Wikimedia Foundation MediaWiki.
How do I fix CVE-2025-32696?
To fix CVE-2025-32696, upgrade to MediaWiki version 1.39.12 or later, 1.42.6 or later, or 1.43.1 or later.
What versions of MediaWiki are affected by CVE-2025-32696?
CVE-2025-32696 affects MediaWiki versions prior to 1.39.12, 1.42.6, and 1.43.1.
What components of MediaWiki are impacted by CVE-2025-32696?
CVE-2025-32696 impacts the includes/actions/RevertAction.php and includes/api/ApiFileRevert.php components of MediaWiki.
Is CVE-2025-32696 a known vulnerability?
Yes, CVE-2025-32696 is a known vulnerability identified by the Wikimedia Foundation affecting MediaWiki.