top of page
perceptive_background_267k.jpg

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after t…

Published:

25 augustus 2026 om 00:00:00

Alert date:

25 augustus 2026 om 15:04:15

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies

CVE-2026-79664 affects Ech0 versions before 4.7.3, where access tokens created with the never-expire option cannot be properly revoked. Three separate revocation mechanisms all fail: the logout function panics on a nil ExpiresAt field, RevokeToken skips revocation when remainTTL is zero, and the admin delete function does not blacklist the JWT ID (JTI). As a result, stolen tokens remain cryptographically valid indefinitely unless the JWT secret is rotated. This allows attackers who obtain a never-expire token to maintain persistent authenticated access to the system. The vulnerability is classified as high severity due to the potential for perpetual unauthorized access. A fix is available in Ech0 version 4.7.3 and later.

Technical details

Mitigation steps:

Affected products:

Ech0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page