Authentication Bypass in Ech0 Comment Panel by Lin-Snow
CVE-2026-79672
7HIGH
What is CVE-2026-79672?
Ech0, before version 4.4.3, contains a significant vulnerability that compromises the integrity of comment moderation. The issue arises from insufficient enforcement of scope-based authorization on nine critical comment panel admin endpoints. As a result, attackers equipped with access tokens with minimal scopes can exploit these unprotected endpoints to execute full comment moderation operations. This includes actions such as listing, approving, rejecting, deleting comments, and altering comment system settings. The potential for abuse positions this vulnerability as a serious concern for website administrators utilizing the affected software.
Affected Version(s)
Ech0 0 < 4.4.3
Ech0 4.4.3
