Authorization Bypass in Ech0 Dashboard Log Endpoints
CVE-2026-79666

7.1HIGH

Key Information:

Vendor

Lin-snow

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79666?

Ech0 versions prior to 4.4.3 are susceptible to an authorization bypass vulnerability that allows authenticated users to access sensitive system logs without proper permission checks. This flaw permits attackers with valid sessions to exploit dashboard log endpoints, specifically allowing access to GET /api/system/logs and the ability to subscribe to Server-Sent Events (SSE) and WebSocket streams. Consequently, attackers can retrieve critical operational data, including file paths, stack traces, and internal URLs, posing a risk to system integrity and data confidentiality.

Affected Version(s)

Ech0 0 < 4.4.3

Ech0 4.4.3

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.