top of page
perceptive_background_267k.jpg

Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in RequireScopes middleware, allowing logged-in non-…

Published:

25 augustus 2026 om 00:00:00

Alert date:

25 augustus 2026 om 15:04:15

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Data Breach & Exfiltration

Ech0 versions before 4.5.1 contain an authorization bypass vulnerability in the RequireScopes middleware. Session tokens skip scope validation, allowing authenticated non-admin users to access admin-only endpoints. Exploiting this flaw, attackers can read system logs, visitor statistics, and user email addresses. They can also subscribe to live WebSocket log streams by sending valid session tokens to unprotected endpoints. The vulnerability requires the attacker to already have a valid session token (i.e., be a logged-in user). No privilege escalation of credentials is needed beyond a standard user account. A fix was introduced in version 4.5.1. The issue is tracked as CVE-2026-79665 and has been assigned a high criticality rating.

Technical details

Mitigation steps:

Affected products:

Ech0 before 4.5.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page