Authentication Bypass in Ech0 by Lin Snow
CVE-2026-79667
7.2HIGH
What is CVE-2026-79667?
Ech0 prior to version 4.4.3 contains a vulnerability where scoped access token restrictions are not properly enforced on several administrative routes. This weak enforcement allows an attacker with a low-scope admin token to access sensitive functions and data beyond their intended privileges. Critical endpoints, such as /api/inbox, /api/panel/comments, and /api/backup/export, fail to validate token scopes, thereby exposing sensitive information and enabling unauthorized actions like exporting a complete database backup. Users are urged to upgrade to version 4.4.3 or later to mitigate this risk.
Affected Version(s)
Ech0 0 < 4.4.3
Ech0 4.4.3
