


Perceptive Security
SOC/SIEM Consultancy

Ech0 before 4.5.1 contains an authorization bypass vulnerability where session tokens skip scope validation in RequireScopes middleware, allowing logged-in non-…
Published:
25 augustus 2026 om 00:00:00
Alert date:
25 augustus 2026 om 15:04:15
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration
Ech0 versions before 4.5.1 contain an authorization bypass vulnerability in the RequireScopes middleware. Session tokens skip scope validation, allowing authenticated non-admin users to access admin-only endpoints. Exploiting this flaw, attackers can read system logs, visitor statistics, and user email addresses. They can also subscribe to live WebSocket log streams by sending valid session tokens to unprotected endpoints. The vulnerability requires the attacker to already have a valid session token (i.e., be a logged-in user). No privilege escalation of credentials is needed beyond a standard user account. A fix was introduced in version 4.5.1. The issue is tracked as CVE-2026-79665 and has been assigned a high criticality rating.
Technical details
Mitigation steps:
Affected products:
Ech0 before 4.5.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-79665
https://github.com/lin-snow/Ech0/security/advisories/GHSA-hmmq-qh6g-6wgh
https://www.vulncheck.com/advisories/ech0-before-authorization-bypass-via-session-tokens
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
