CVE-2026-79672
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
25/08/2026
Last modified:
31/08/2026
Description
Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments, and modify comment system settings by directly accessing the unprotected panel endpoints.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
5.50
Severity 3.x
MEDIUM



