CVE-2026-33638: ECH0
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/allusers` is mounted as a public endpoint and returns user records without authentication. This allows remote unauthenticated user enumeration and exposure of user profile metadata. A fix is available in v4.2.0.
Affected products
- ECH0 ECH0: before 4.2.0 (fixed in 4.2.0)
Published 2026-03-26. Last modified 2026-06-17.