{"apiVersion":"1.0","identifier":"CVE-2026-79667","description":"Ech0 version 4.3.4 and earlier fails to reliably enforce scoped access token (least-privilege) restrictions on several privileged admin routes. Multiple privileged endpoints (e.g., /api/inbox, /api/panel/comments, /api/backup/export) omit scope checks and authorize based only on the user-s admin role, and the backup export handler discards token scope metadata entirely. An attacker holding a deliberately limited (low-scope) admin access token can reach broader privileged functionality than intended, including reading the inbox and exporting a full database backup ZIP archive. Fixed in 4.4.3.","publishedAt":"2026-08-25T12:16:34","lastModifiedAt":"2026-08-25T14:16:58","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79667","cvssScore":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","epssProbability":0.0019,"riskScore":0.77,"affectedProduct":"Ech0","affectedVersions":"<=4.3.4","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-79667","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-79667","en":"https://www.redsauce.net/en/cves/CVE-2026-79667","fr":"https://www.redsauce.net/fr/cves/CVE-2026-79667","pt":"https://www.redsauce.net/pt/cves/CVE-2026-79667","de":"https://www.redsauce.net/de/cves/CVE-2026-79667","sk":"https://www.redsauce.net/sk/cves/CVE-2026-79667","el":"https://www.redsauce.net/el/cves/CVE-2026-79667"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-79667"}}