PT-2026-27633 · Ech0 · Ech0

Qiaonpc

·

Publicado

2026-03-24

·

Atualizado

2026-03-27

·

CVE-2026-33638

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ech0 versions prior to 4.2.0
Description The GET /api/allusers API endpoint is publicly accessible, allowing remote unauthenticated user enumeration and exposure of user profile metadata. The route is registered under public routes in internal/router/user.go:17 and is called using appRouterGroup.PublicRouterGroup.GET("/allusers", h.UserHandler.GetAllUsers()). Despite API documentation indicating an authentication requirement (@Security ApiKeyAuth), the endpoint does not enforce it. This allows unauthorized access to user data, potentially enabling account reconnaissance and targeted credential attacks.
Recommendations Update Ech0 to version 4.2.0 or later.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33638
GHSA-M983-7426-5HRJ
GO-2026-4838
SUSE-SU-2026:1135-1

Produtos afetados

Ech0