CVE-2026-79672: Lin-Snow ECH0
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation operations. Attackers with a limited-scope access token can list, approve, reject, delete comments, and modify comment system settings by directly accessing the unprotected panel endpoints.
Affected products
- Lin-Snow ECH0: before 4.4.3 (fixed in 4.4.3)
Published 2026-08-25. Last modified 2026-08-31.