CVE-2026-5266
published 2026-05-11CVE-2026-5266: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated with program files…
PriorityP412low2.3CVSS 4.0
AVNACLATPPRLUINVCLVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.25%
16.1th percentile
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo.
This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php.
This issue affects Echo: from * before 1.43.7, 1.44.4, 1.45.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.43.8+dfsg-1 (forky) | mediawiki 1:1.43.8+dfsg-1 (forky) |
| wikimedia_foundation | echo | >= * < 1.43.7, 1.44.4, 1.45.2 | 1.43.7, 1.44.4, 1.45.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vmww-wfjj-w6p8: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo
ghsa_unreviewed·2026-05-11
CVE-2026-5266 [LOW] CWE-200 GHSA-vmww-wfjj-w6p8: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo.
This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php.
This issue affects Echo: from * before 1.43.7, 1.44.4, 1.45.2.
VulDB
Wikimedia Echo up to 1.43.6/1.44.3/1.45.1 ApiEchoNotifications.Php information disclosure (EUVD-2026-29157)
vuldb·2026-05-11·CVSS 2.3
CVE-2026-5266 [LOW] Wikimedia Echo up to 1.43.6/1.44.3/1.45.1 ApiEchoNotifications.Php information disclosure (EUVD-2026-29157)
A vulnerability was found in Wikimedia Echo up to 1.43.6/1.44.3/1.45.1. It has been rated as problematic. This affects an unknown function of the file includes/Api/ApiEchoNotifications.Php. Performing a manipulation results in information disclosure.
This vulnerability was named CVE-2026-5266. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
Debian
CVE-2026-5266: mediawiki
vendor_debian·2026
CVE-2026-5266 [LOW] CVE-2026-5266: mediawiki
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:1.43.8+dfsg-1)
sid: resolved (fixed in 1:1.43.8+dfsg-1)
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-11
Published