Junglewise Threat Intelligence

CVE-2026-79669: Ech0 missing authorization on system log endpoints

CVE-2026-79669 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: github.com/lin-snow/ech0 (Go), Lin-Snow Ech0. Vendors: Go, Lin-Snow.

Executive brief

Ech0 is a logging and monitoring system used to track server activity and application state. A flaw allows any registered user—not just administrators—to read historical system logs and stream real-time logs via multiple endpoints. An attacker can extract sensitive information such as internal file paths, error traces, database details, and user activity, which can be used to plan more sophisticated attacks on the application.

Technical details

This is a missing authorization vulnerability (CWE-862) in the system log endpoints: GET /api/system/logs, GET /api/system/logs/stream, and WS /ws/system/logs. The vulnerable code in internal/router/dashboard.go registers these endpoints on the AuthRouterGroup without RequireScopes middleware, and the WSRouterGroup applies no authorization middleware at all. While the endpoints require JWT authentication (any logged-in user), they fail to check whether the user has admin privileges before granting access to sensitive logs. An attacker with a non-admin account can read full historical logs and subscribe to real-time streams, exposing internal file paths, error stack traces, module names, and structured log fields. The fix is to add RequireScopes(ScopeAdminSettings) middleware to all three endpoints, as implemented in patched version 4.4.3.

Affected products

  • lin-snow Ech0 before 4.4.3

Timeline

  • 2026-08-25: disclosed
  • 2026-04-09: patched: Patch released as version 4.4.3

References

Related threats