<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-79665 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-79665/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 25 Aug 2026 14:08:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-79665/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass Vulnerability in Ech0</title><link>https://feed.craftedsignal.io/briefs/2026-08-ech0-auth-bypass/</link><pubDate>Tue, 25 Aug 2026 14:08:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ech0-auth-bypass/</guid><description>Ech0 versions prior to 4.5.1 are vulnerable to an authorization bypass in the RequireScopes middleware, allowing non-admin users to access sensitive administrative functions.</description><content:encoded><![CDATA[<p>Ech0 versions prior to 4.5.1 contain a critical authorization bypass vulnerability (CVE-2026-79665) stemming from insufficient validation of session tokens within the application's 'RequireScopes' middleware. This flaw effectively permits authenticated, non-privileged users to circumvent intended access controls and interact with administrative endpoints.</p>
<p>By leveraging existing session tokens, an attacker can access sensitive information including system logs, visitor statistics, and user email addresses. Furthermore, the vulnerability allows for the subscription to live WebSocket logs, providing a mechanism for real-time reconnaissance or data exfiltration. This vulnerability poses a significant risk to the confidentiality and integrity of the application, as it grants administrative-level access without the appropriate scope or permission level. The vulnerability is assigned to the 'lin-snow' organization.</p>
<h2 id="impact">Impact</h2>
<p>The impact of this vulnerability includes the unauthorized exposure of system logs, internal visitor statistics, and user emails. Furthermore, the ability to subscribe to live WebSocket logs enables an attacker to monitor application traffic and activity in real time. This unauthorized access can lead to significant data breaches and internal system discovery, compromising the overall security of the Ech0 deployment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Ech0 to version 4.5.1 or later to remediate CVE-2026-79665.</li>
<li>Review web server access logs for anomalous requests to administrative endpoints originating from non-admin user sessions.</li>
<li>Monitor for unusual patterns in WebSocket traffic or unauthorized subscription attempts to system log streams.</li>
<li>Review user roles and privileges to ensure that sessions currently in use do not hold excessive permissions.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authorization-bypass</category><category>web-application</category><category>cve-2026-79665</category></item></channel></rss>