PT-2026-81283 · Ech0 · Ech0

·

CVE-2026-79664

·

Published

2026-05-07

·

Updated

2026-08-25

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.7.3
Description Failure to properly revoke access tokens created with the never-expire option allows attackers to maintain perpetual authenticated access following token theft. This occurs because three revocation mechanisms are flawed: the logout process panics when encountering a nil ExpiresAt field, the RevokeToken() function skips execution when remainTTL is zero, and the admin delete function fails to blacklist the JTI (JWT ID), leaving stolen tokens cryptographically valid until the JWT secret is rotated.
Recommendations Update to version 4.7.3 or later. Rotate the JWT secret to invalidate all existing tokens.

Exploit

Fix

Insufficient Session Expiration

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79664
GHSA-FPW6-HRG5-Q5X5
GO-2026-5375

Affected Products

Ech0