Junglewise Threat Intelligence

CVE-2026-79667: Ech0 scoped access token bypass in admin routes

CVE-2026-79667 · Severity: high · CVSS 7.6 · Published 2026-08-25

Technologies: github.com/lin-snow/ech0 (Go), Lin-Snow Ech0. Vendors: Go, Lin-Snow.

Executive brief

Ech0 is an open-source application platform that uses access tokens to enforce least-privilege access controls for admin functions. Due to incomplete scope enforcement on several critical admin endpoints, an attacker with a deliberately limited access token can bypass those restrictions to access sensitive functions including reading inbox messages and exporting complete database backups. This allows an attacker to escalate privileges and exfiltrate all application data.

Technical details

The vulnerability is a privilege escalation flaw in Ech0's token scope enforcement mechanism (CWE-285). The application implements an opt-in scope validation middleware (RequireScopes), but multiple privileged routes—including /api/inbox, /api/panel/comments, /api/backup/export, and /api/migration—omit these checks and authorize only based on the user's admin role flag. The backup export handler is particularly vulnerable: it parses the token and rebuilds a viewer context from only the user ID, discarding all token metadata including scopes and token type. An attacker with a low-scope admin token (e.g., scoped only for "echo:read") can exploit this to access privileged operations and export database backups. No user interaction is required; the attacker only needs to hold a valid (though deliberately limited) admin access token. The issue is fixed in version 4.4.3.

Affected products

  • lin-snow Ech0 4.3.4 and earlier

Timeline

  • 2026-08-25: disclosed
  • 2026-04-09: patched: Fixed in version 4.4.3

References

Related threats