Executive brief
A security flaw was identified in the Wikimedia Echo extension, which provides notification services for MediaWiki sites. The system failed to properly restrict access to user notifications, allowing any authorized third-party tool or bot to read a user's private alerts without specific permission. This could lead to the exposure of sensitive information such as email subjects or private interaction details.
Technical details
An information disclosure vulnerability exists in the Wikimedia Echo extension's API (specifically in ApiEchoNotifications.php). The root cause is a lack of a specific user right or OAuth grant requirement to fetch notifications, allowing any authenticated BotPassword or OAuth tool to access a user's notification stream. This stream can contain sensitive data such as email subject lines or 'thanks' notifications. The fix introduces a new 'echo-read-notifications' user right and associated OAuth grant to enforce proper authorization. The issue is resolved in versions 1.43.7, 1.44.4, and 1.45.2.
Affected products
- Wikimedia Foundation Echo Before 1.43.7, 1.44.4, 1.45.2
Timeline
- 2026-03-15: disclosed: Vulnerability reported via Phabricator
- 2026-03-31: patched: Patches developed and merged into various branches
- 2026-05-11: advisory: CVE-2026-5266 published