CVE-2026-7166Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ fields. This vulnerability is also present in the local database, as it contains accessible sensitive information such as data on minors and municipal users. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain access to sensitive information and data.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-22: 3Technical Details · 2026-06-22: 306-22
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7166 Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ … https://www.cve.org/CVERecord?id=CVE-2026-7166 ----- Traducción: CVE-2026-7166 Vul… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑7166, describing an API that unintentionally exposes email and phone number data, without any mention of exploitation, mitigation, or proof‑of‑concept.

    0000048
    88 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-7166 Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ … https://www.cve.org/CVERecord?id=CVE-2026-7166

    Post summary

    The post announces CVE-2026-7166 as a data exposure flaw exposing email and phone details via an API, with no proof of exploitation, active usage, or remediation highlighted.

    00000716
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7166 Unauthenticated API Information Disclosure Exposing Email and Phone Number Data https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7166

    Post summary

    The post is a concise disclosure of CVE‑2026‑7166, describing an unauthenticated API information‑disclosure flaw that leaks email and phone numbers, with no evidence of exploitation, patches, or false‑positive claims.

    00000110
    4.1K followersView on X

Explore more