PT-2026-81291 · Ech0 · Ech0

·

CVE-2026-79672

·

Published

2026-04-10

·

Updated

2026-08-25

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.4.3
Description Insufficient scope-based authorization on nine comment panel admin endpoints allows users with access tokens possessing minimal scopes to perform full comment moderation operations. This enables attackers to list, approve, reject, and delete comments, as well as modify comment system settings by directly accessing these unprotected endpoints.
Recommendations Update to version 4.4.3 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79672
GHSA-FWG7-53P4-G33C
GO-2026-5382

Affected Products

Ech0