SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-79672

MEDIUM · CVSS 5.5 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Ech0 versions prior to 4.4.3 are vulnerable due to inadequate scope-based authorization on nine admin endpoints related to comment moderation. This flaw allows attackers with limited-scope access tokens to perform critical actions such as listing, approving, rejecting, and deleting comments, as well as modifying system settings. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized comment management and potential abuse.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79672
Severity
MEDIUM
CVSS
5.5
EPSS
0.19%

Original NVD Description

Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments, and modify comment system settings by directly accessing the unprotected panel endpoints.