PT-2026-81287 · Ech0 · Ech0

·

CVE-2026-79668

·

Published

2026-05-07

·

Updated

2026-08-25

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.7.3
Description An authentication bypass exists in the 'PUT /api/echo/like/:id' endpoint, allowing unauthenticated attackers to increment engagement metrics without identity verification or rate limiting. By sending repeated requests, attackers can arbitrarily inflate the fav count field for any known echo identifier, which compromises the integrity of social ranking systems and engagement metrics.
Recommendations Update to version 4.7.3 or later. As a temporary workaround, restrict access to the 'PUT /api/echo/like/:id' endpoint to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79668
GHSA-RGJ7-VG8V-J4WR
GO-2026-5623

Affected Products

Ech0