Authentication Bypass in Ech0 by Lin Snow
CVE-2026-79667

7.2HIGH

Key Information:

Vendor

Lin-snow

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79667?

Ech0 prior to version 4.4.3 contains a vulnerability where scoped access token restrictions are not properly enforced on several administrative routes. This weak enforcement allows an attacker with a low-scope admin token to access sensitive functions and data beyond their intended privileges. Critical endpoints, such as /api/inbox, /api/panel/comments, and /api/backup/export, fail to validate token scopes, thereby exposing sensitive information and enabling unauthorized actions like exporting a complete database backup. Users are urged to upgrade to version 4.4.3 or later to mitigate this risk.

Affected Version(s)

Ech0 0 < 4.4.3

Ech0 4.4.3

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.