CVE-2026-5266 Details
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php. This issue affects Echo: from * before 1.43.7, 1.44.4, 1.45.2.
A vulnerability in the Wikimedia Foundation Echo extension allows any OAuth tool or BotPassword to access a user's notifications without the necessary permissions. This issue affects Echo versions prior to 1.43.7, 1.44.4, and 1.45.2. The notifications API can inadvertently expose private information, such as email subject lines or acknowledgments.
A new user right grant called 'echo-read-notifications' has been created and is now available to all users. Tools that need access to user notifications must request this grant.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://phabricator.wikimedia.org/T420154 | wikimedia-foundation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | wikimedia-foundation |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | wikimedia-foundation |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | wikimedia-foundation |