CVE-2026-79672: Ech0 before 4.4.3 Authentication Bypass via Comment Panel

Published Aug 25, 2026
·
Updated

Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments, and modify comment system settings by directly accessing the unprotected panel endpoints.

Affected Software

1 affected component
Ech0<4.4.3

Event History

Aug 25, 2026
CVE Published
via MITRE·11:33 AM
Data Sourced
via MITRE·11:33 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs an Ech0 access token with minimal scopes. No user interaction is required, and the vulnerable endpoints are reachable over the network.

2

What actions can a limited-scope token perform?

It can access nine comment panel administration endpoints to list, approve, reject, and delete comments, and to modify comment system settings.

3

Which versions are affected?

Ech0 versions before 4.4.3 are affected. Upgrading to 4.4.3 or later addresses the reported authorization enforcement failure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203