CVE-2026-29788: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-29788 is an integrity tampering vulnerability in TSPortal, the WikiTide Foundation's in-house Trust and Safety platform used to manage reports, investigations, appeals, and transparency work. The flaw allows any unauthenticated network attacker to forge Data Protection Act (DPA) reports so they appear as genuine self-deletion requests from arbitrary users. All versions prior to v30 (i.e., ≤ v29) of the miraheze/ts-portal Composer package are affected. The vulnerability was published on March 4, 2026, and patched in version 30. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.4 (High) (GitHub Advisory, GitHub Advisory DB).

Technical details

The root cause is TSPortal's Laravel middleware behavior (convertEmptyStringsToNull), which silently converts empty string inputs to null values before they reach application logic — classified as CWE-283 (Unverified Ownership) and CWE-1287 (Improper Validation of Specified Type of Input). When a DPA report is submitted with the "The above username is... someone who I suspect is under the age of 13" field selected and the Evidence field left empty, the null conversion causes the resulting record to be indistinguishable from a legitimate user self-deletion request. The Http/Controllers/DPAController::store() method performs no validation to ensure the evidence field is non-empty, allowing the forged report to pass through without detection. The fix involves either disabling convertEmptyStringsToNull in the middleware or adding server-side validation in the controller (GitHub Advisory).

Impact

Successful exploitation allows an attacker to fraudulently trigger the deletion of any arbitrary user's data by making a forged DPA report appear as a legitimate self-deletion request. Because the ingenuine report is indistinguishable from a genuine one, Trust and Safety staff may action it, resulting in unauthorized data deletion both within TSPortal and in any downstream systems that process these requests. There is no confidentiality impact, but integrity and availability of user records are significantly compromised, with potential cascading effects if actioned across integrated systems (GitHub Advisory, GitHub Advisory DB).

Exploitability

A proof-of-concept exploit sequence is publicly documented in the GitHub Security Advisory, requiring no authentication, no special privileges, and only passive user interaction (a Trust and Safety staff member must review and action the report). The EPSS score is approximately 0.034% (10th percentile), indicating a low but non-zero probability of exploitation in the wild. There is currently no evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, GitHub Advisory DB).

Exploitation steps

  1. Identify target: Confirm the TSPortal instance is running a version ≤ v29 of miraheze/ts-portal.
  2. Access DPA report submission: Navigate to the TSPortal DPA report creation interface (no authentication required based on the CVSS PR:N metric).
  3. Select the target field value: In the "The above username is..." field, select the option "...someone who I suspect is under the age of 13" and specify the target username whose data deletion is desired.
  4. Leave Evidence field empty: Do not enter any content in the "Evidence" field, allowing the Laravel convertEmptyStringsToNull middleware to convert the empty string to null.
  5. Submit the report: Submit the form. The resulting database record will be indistinguishable from a genuine user self-deletion request due to the null evidence field.
  6. Await staff action: A Trust and Safety team member reviewing the queue may process the forged report as a legitimate self-deletion, triggering unauthorized deletion of the targeted user's data in TSPortal and any integrated downstream systems (GitHub Advisory).

Indicators of compromise

  • Logs: DPA report submissions in TSPortal audit logs where the Evidence field is null or empty, particularly those categorized as self-deletion requests — review for reports submitted by accounts other than the reported user.
  • Database: DPA records in the database where the evidence column is NULL and the report type corresponds to self-deletion, especially if the submitter and reported user differ.
  • Application Logs: Unexpected volume of DPA/self-deletion report submissions from a single IP address or user account in a short time window.
  • Miraheze Issue Tracker: Cross-reference flagged reports against the issue tracker (T15053) for any anomalous patterns prior to the patch being applied (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade TSPortal to version 30 or later, which patches this vulnerability (GitHub Advisory). As a workaround for instances that cannot immediately upgrade, operators should either disable the convertEmptyStringsToNull middleware behavior in Laravel or add server-side validation in Http/Controllers/DPAController::store() to reject submissions with an empty Evidence field. Additionally, administrators should audit existing DPA records for any reports with null evidence fields that were categorized as self-deletion requests, and manually verify their legitimacy.

Community reactions

A technical write-up was published at infinitsec.net covering the vulnerability under the title "TSPortal: Anyone Can Forge Self-Deletion Requests of Any User," indicating some community security researcher interest. The vulnerability was also indexed by Red Hat's CVE tracking and ENISA's EUVD (EUVD-2026-10067), reflecting standard cross-industry cataloging. No significant vendor statements beyond the original GitHub Security Advisory or notable social media discussion have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management