


Perceptive Security
SOC/SIEM Consultancy

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after t…
Published:
25 augustus 2026 om 00:00:00
Alert date:
25 augustus 2026 om 15:04:15
Source:
nvd.nist.gov
Identity & Access, Web Technologies
CVE-2026-79664 affects Ech0 versions before 4.7.3, where access tokens created with the never-expire option cannot be properly revoked. Three separate revocation mechanisms all fail: the logout function panics on a nil ExpiresAt field, RevokeToken skips revocation when remainTTL is zero, and the admin delete function does not blacklist the JWT ID (JTI). As a result, stolen tokens remain cryptographically valid indefinitely unless the JWT secret is rotated. This allows attackers who obtain a never-expire token to maintain persistent authenticated access to the system. The vulnerability is classified as high severity due to the potential for perpetual unauthorized access. A fix is available in Ech0 version 4.7.3 and later.
Technical details
Mitigation steps:
Affected products:
Ech0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-79664
https://github.com/lin-snow/Ech0/security/advisories/GHSA-fpw6-hrg5-q5x5
https://www.vulncheck.com/advisories/ech0-before-access-token-revocation-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
