← Terug naar overzicht

Ech0 versions before 4.5.1 contain an authorization bypass vulnerability in the RequireScopes middleware. Session tokens skip scope validation, allowing authenticated non-admin users to access admin-only endpoints. Exploiting this flaw, attackers can read system logs, visitor statistics, and user email addresses. They can also subscribe to live WebSocket log streams by sending valid session tokens to unprotected endpoints. The vulnerability requires the attacker to already have a valid session token (i.e., be a logged-in user). No privilege escalation of credentials is needed beyond a standard user account. A fix was introduced in version 4.5.1. The issue is tracked as CVE-2026-79665 and has been assigned a high criticality rating.

Affected products

  • Ech0 before 4.5.1

Related CVE's

  • CVE-2026-79665

Categories

  • Data Breach & Exfiltration
  • Identity & Access
  • Web Technologies