Medium severity5.5NVD Advisory· Published Aug 25, 2026· Updated Aug 25, 2026
CVE-2026-79672
CVE-2026-79672
Description
Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments, and modify comment system settings by directly accessing the unprotected panel endpoints.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.