cbcvebase.
CVE-2026-5266
published 2026-05-11

CVE-2026-5266: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated with program files…

PriorityP412low2.3CVSS 4.0
AVNACLATPPRLUINVCLVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.25%
16.1th percentile
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php. This issue affects Echo: from * before 1.43.7, 1.44.4, 1.45.2.

Affected

2 ranges
VendorProductVersion rangeFixed in
debianmediawiki< mediawiki 1:1.43.8+dfsg-1 (forky)mediawiki 1:1.43.8+dfsg-1 (forky)
wikimedia_foundationecho>= * < 1.43.7, 1.44.4, 1.45.21.43.7, 1.44.4, 1.45.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.