CVE-2026-5266

Published: Mag 11, 2026 Last Modified: Mag 11, 2026
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,3
Source: c4f26cc8-17ff-4c99-b5e2-38fc1793eacc
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo.

This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php.

This issue affects Echo: from * before 1.43.7, 1.44.4, 1.45.2.

200

Exposure of Sensitive Information to an Unauthorized Actor

Draft
Common Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies: Mobile, Not Technology-Specific, Web Based
View CWE Details
https://phabricator.wikimedia.org/T420154