Remote User Enumeration Vulnerability in Ech0 Publishing Platform
CVE-2026-33638
5.3MEDIUM
What is CVE-2026-33638?
The Ech0 publishing platform, known for its open-source, self-hosted capabilities for personal idea sharing, has a vulnerability that exposes user records without authentication. The endpoint GET /api/allusers was publicly accessible prior to version 4.2.0, allowing remote attackers to enumerate users and retrieve sensitive profile metadata. This flaw poses a significant risk as it enables unauthorized parties to gather information about user accounts, highlighting the need for users to upgrade to the fixed version (4.2.0) to mitigate potential data breaches.
Affected Version(s)
Ech0 < 4.2.0
