Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains a README and a single Python 3 proof-of-concept, poc.py, for CVE-2026-102973. The PoC compares MediaWiki's Special:EmailUser web form with the action=emailuser API path. It authenticates as a supplied disposable account, obtains MediaWiki login and CSRF tokens, confirms that the web form is denied by a local EmailUserAuthorizeSend policy hook, and then makes the corresponding API request. A successful API call without the policy marker is reported as reproduction of the authorization-hook bypass. The code is deliberately constrained to HTTP(S) loopback hosts, validates redirect destinations remain loopback, requires an explicit local-SMTP flag plus typed confirmation, and prompts interactively for the password. It is a configuration-dependent validation PoC rather than a general-purpose exploitation framework; its only message payload is a fixed benign test email intended for a local SMTP sink.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.