Junglewise Threat Intelligence

CVE-2026-79673: Ech0 scope bypass in PUT /user endpoint via profile:read token

CVE-2026-79673 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: github.com/lin-snow/ech0 (Go), Lin-Snow Ech0. Vendors: Go, Lin-Snow.

Executive brief

Ech0 is an API platform that uses access tokens with granular permission scopes to control what operations different integrations can perform. A critical flaw allows an attacker with a read-only "profile:read" token to bypass scope restrictions, change an admin's password, and escalate to a fully unrestricted admin session—completely circumventing the permission system and enabling account takeover.

Technical details

This is an authorization bypass (CWE-863) stemming from incorrect scope enforcement on the PUT /user endpoint. The endpoint is protected only by RequireScopes("profile:read"), a read-only scope, yet performs privileged write operations including password changes. The vulnerable code path: UpdateUser() accepts password changes without verifying write-level scope sufficiency; the scope middleware bypasses all checks for session tokens; after password change, POST /login issues an unrestricted session token that bypasses all subsequent scope enforcement. An attacker with an admin's profile:read access token (e.g., from compromised integration or log leak) can: (1) call PUT /user to change the admin's password, (2) login with new credentials to obtain a session token, (3) use the session token for unrestricted admin API access. Patch released in version 4.4.3 adds a profile:write scope and requires it for the PUT /user endpoint.

Affected products

  • lin-snow Ech0 before 4.4.3

Timeline

  • 2026-04-09: disclosed
  • 2026-08-25: advisory
  • 2026-04-09: patched: Version 4.4.3 released

References

Related threats