CVE-2026-79672: Ech0 before 4.4.3 Authentication Bypass via Comment Panel
Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments, and modify comment system settings by directly accessing the unprotected panel endpoints.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an Ech0 access token with minimal scopes. No user interaction is required, and the vulnerable endpoints are reachable over the network.
What actions can a limited-scope token perform?
It can access nine comment panel administration endpoints to list, approve, reject, and delete comments, and to modify comment system settings.
Which versions are affected?
Ech0 versions before 4.4.3 are affected. Upgrading to 4.4.3 or later addresses the reported authorization enforcement failure.