CVE-2026-79673
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
25/08/2026
Last modified:
26/08/2026
Description
Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with an admin's profile:read access token can change the admin's password and login to obtain an unrestricted session token that bypasses all scope enforcement.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM



