
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-29788 is an integrity tampering vulnerability in TSPortal, the WikiTide Foundation's in-house Trust and Safety platform used to manage reports, investigations, appeals, and transparency work. The flaw allows any unauthenticated network attacker to forge Data Protection Act (DPA) reports so they appear as genuine self-deletion requests from arbitrary users. All versions prior to v30 (i.e., ≤ v29) of the miraheze/ts-portal Composer package are affected. The vulnerability was published on March 4, 2026, and patched in version 30. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.4 (High) (GitHub Advisory, GitHub Advisory DB).
The root cause is TSPortal's Laravel middleware behavior (convertEmptyStringsToNull), which silently converts empty string inputs to null values before they reach application logic — classified as CWE-283 (Unverified Ownership) and CWE-1287 (Improper Validation of Specified Type of Input). When a DPA report is submitted with the "The above username is... someone who I suspect is under the age of 13" field selected and the Evidence field left empty, the null conversion causes the resulting record to be indistinguishable from a legitimate user self-deletion request. The Http/Controllers/DPAController::store() method performs no validation to ensure the evidence field is non-empty, allowing the forged report to pass through without detection. The fix involves either disabling convertEmptyStringsToNull in the middleware or adding server-side validation in the controller (GitHub Advisory).
Successful exploitation allows an attacker to fraudulently trigger the deletion of any arbitrary user's data by making a forged DPA report appear as a legitimate self-deletion request. Because the ingenuine report is indistinguishable from a genuine one, Trust and Safety staff may action it, resulting in unauthorized data deletion both within TSPortal and in any downstream systems that process these requests. There is no confidentiality impact, but integrity and availability of user records are significantly compromised, with potential cascading effects if actioned across integrated systems (GitHub Advisory, GitHub Advisory DB).
A proof-of-concept exploit sequence is publicly documented in the GitHub Security Advisory, requiring no authentication, no special privileges, and only passive user interaction (a Trust and Safety staff member must review and action the report). The EPSS score is approximately 0.034% (10th percentile), indicating a low but non-zero probability of exploitation in the wild. There is currently no evidence of active in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, GitHub Advisory DB).
miraheze/ts-portal.convertEmptyStringsToNull middleware to convert the empty string to null.The primary remediation is to upgrade TSPortal to version 30 or later, which patches this vulnerability (GitHub Advisory). As a workaround for instances that cannot immediately upgrade, operators should either disable the convertEmptyStringsToNull middleware behavior in Laravel or add server-side validation in Http/Controllers/DPAController::store() to reject submissions with an empty Evidence field. Additionally, administrators should audit existing DPA records for any reports with null evidence fields that were categorized as self-deletion requests, and manually verify their legitimacy.
A technical write-up was published at infinitsec.net covering the vulnerability under the title "TSPortal: Anyone Can Forge Self-Deletion Requests of Any User," indicating some community security researcher interest. The vulnerability was also indexed by Red Hat's CVE tracking and ENISA's EUVD (EUVD-2026-10067), reflecting standard cross-industry cataloging. No significant vendor statements beyond the original GitHub Security Advisory or notable social media discussion have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."