Authentication Bypass in Ech0 Comment Panel by Lin-Snow
CVE-2026-79672

7HIGH

Key Information:

Vendor

Lin-snow

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79672?

Ech0, before version 4.4.3, contains a significant vulnerability that compromises the integrity of comment moderation. The issue arises from insufficient enforcement of scope-based authorization on nine critical comment panel admin endpoints. As a result, attackers equipped with access tokens with minimal scopes can exploit these unprotected endpoints to execute full comment moderation operations. This includes actions such as listing, approving, rejecting, deleting comments, and altering comment system settings. The potential for abuse positions this vulnerability as a serious concern for website administrators utilizing the affected software.

Affected Version(s)

Ech0 0 < 4.4.3

Ech0 4.4.3

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

offset
.