PT-2026-81280 · Ech0 · Ech0

·

CVE-2026-79661

·

Published

2026-05-07

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.7.3
Description The application registers the 'PUT /api/echo/like/:id' endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav count counter of any echo, including private ones, by providing its UUID, which can be obtained from the 'GET /api/echo/page' feed. Because repeated requests are accepted without deduplication, each request triggers a database write and a four-key cache invalidation, enabling attackers to inflate popularity metrics and increase the load on the database and cache.
Recommendations Update to version 4.7.3.

Exploit

Fix

Missing Authorization

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79661
GHSA-PJ6Q-4VQ4-R8CG
GO-2026-5541

Affected Products

Ech0