{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-79665/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-79665"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CVE-2026-79665\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Ech0"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","web-application","cve-2026-79665"],"_cs_type":"advisory","_cs_vendors":["lin-snow"],"content_html":"\u003cp\u003eEch0 versions prior to 4.5.1 contain a critical authorization bypass vulnerability (CVE-2026-79665) stemming from insufficient validation of session tokens within the application's 'RequireScopes' middleware. This flaw effectively permits authenticated, non-privileged users to circumvent intended access controls and interact with administrative endpoints.\u003c/p\u003e\n\u003cp\u003eBy leveraging existing session tokens, an attacker can access sensitive information including system logs, visitor statistics, and user email addresses. Furthermore, the vulnerability allows for the subscription to live WebSocket logs, providing a mechanism for real-time reconnaissance or data exfiltration. This vulnerability poses a significant risk to the confidentiality and integrity of the application, as it grants administrative-level access without the appropriate scope or permission level. The vulnerability is assigned to the 'lin-snow' organization.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of this vulnerability includes the unauthorized exposure of system logs, internal visitor statistics, and user emails. Furthermore, the ability to subscribe to live WebSocket logs enables an attacker to monitor application traffic and activity in real time. This unauthorized access can lead to significant data breaches and internal system discovery, compromising the overall security of the Ech0 deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Ech0 to version 4.5.1 or later to remediate CVE-2026-79665.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous requests to administrative endpoints originating from non-admin user sessions.\u003c/li\u003e\n\u003cli\u003eMonitor for unusual patterns in WebSocket traffic or unauthorized subscription attempts to system log streams.\u003c/li\u003e\n\u003cli\u003eReview user roles and privileges to ensure that sessions currently in use do not hold excessive permissions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T16:16:43Z","date_published":"2026-08-25T14:08:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ech0-auth-bypass/","summary":"Ech0 versions prior to 4.5.1 are vulnerable to an authorization bypass in the RequireScopes middleware, allowing non-admin users to access sensitive administrative functions.","title":"Authorization Bypass Vulnerability in Ech0","url":"https://feed.craftedsignal.io/briefs/2026-08-ech0-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-79665","version":"https://jsonfeed.org/version/1.1"}