CVE-2026-5266: Infoleak
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo.
This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php.
This issue affects Echo: from before 1.43.7, 1.44.4, 1.45.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5266?
CVE-2026-5266 is classified as a moderate severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2026-5266?
To fix CVE-2026-5266, upgrade Wikimedia Foundation Echo to versions 1.43.7 or later, 1.44.4 or later, or 1.45.2 or later.
What systems are affected by CVE-2026-5266?
CVE-2026-5266 affects Wikimedia Foundation Echo versions prior to 1.43.7, 1.44.4, and 1.45.2.
What kind of information is exposed due to CVE-2026-5266?
CVE-2026-5266 may expose sensitive information to unauthorized actors through the Echo notifications component.
Is CVE-2026-5266 a remote vulnerability?
Yes, CVE-2026-5266 is considered a remote vulnerability as it can be exploited over the network without physical access.