PT-2026-81288 · Ech0 · Ech0
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ech0 versions prior to 4.4.3
Description
Insufficient authorization checks on system log endpoints allow authenticated non-admin users to read and stream all server logs. This enables the collection of reconnaissance data, such as internal file paths, error stack traces, and application state, through the following endpoints:
- GET '/api/system/logs'
- GET '/api/system/logs/stream'
- WS '/ws/system/logs'
Recommendations
Update to version 4.4.3 or later.
Restrict access to the '/api/system/logs', '/api/system/logs/stream', and '/ws/system/logs' endpoints to prevent unauthorized log access.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ech0