CVE-2026-79673: Lin-Snow ECH0
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with an admin's profile:read access token can change the admin's password and login to obtain an unrestricted session token that bypasses all scope enforcement.
Affected products
- Lin-Snow ECH0: before 4.4.3 (fixed in 4.4.3)
Published 2026-08-25. Last modified 2026-08-31.