Remote User Enumeration Vulnerability in Ech0 Publishing Platform
CVE-2026-33638

5.3MEDIUM

Key Information:

Vendor

Lin-snow

Status
Vendor
CVE Published:
26 March 2026

What is CVE-2026-33638?

The Ech0 publishing platform, known for its open-source, self-hosted capabilities for personal idea sharing, has a vulnerability that exposes user records without authentication. The endpoint GET /api/allusers was publicly accessible prior to version 4.2.0, allowing remote attackers to enumerate users and retrieve sensitive profile metadata. This flaw poses a significant risk as it enables unauthorized parties to gather information about user accounts, highlighting the need for users to upgrade to the fixed version (4.2.0) to mitigate potential data breaches.

Affected Version(s)

Ech0 < 4.2.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.