PT-2026-81284 · Ech0 · Ech0

·

CVE-2026-79665

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.5.1
Description An authorization bypass occurs because session tokens skip scope validation within the RequireScopes middleware. This allows authenticated users without administrative privileges to access administrative endpoints. By providing authenticated session tokens, attackers can retrieve system logs, visitor statistics, and user emails, as well as subscribe to live WebSocket logs.
Recommendations Update to version 4.5.1 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79665
GHSA-HMMQ-QH6G-6WGH

Affected Products

Ech0