PT-2026-81288 · Ech0 · Ech0

·

CVE-2026-79669

·

Published

2026-04-10

·

Updated

2026-08-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.4.3
Description Insufficient authorization checks on system log endpoints allow authenticated non-admin users to read and stream all server logs. This enables the collection of reconnaissance data, such as internal file paths, error stack traces, and application state, through the following endpoints:
  • GET '/api/system/logs'
  • GET '/api/system/logs/stream'
  • WS '/ws/system/logs'
Recommendations Update to version 4.4.3 or later. Restrict access to the '/api/system/logs', '/api/system/logs/stream', and '/ws/system/logs' endpoints to prevent unauthorized log access.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79669
GHSA-W8JJ-CWMC-WGQ2
GO-2026-5701

Affected Products

Ech0