Report: CVE-2026-33638 - Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint

Report: CVE-2026-33638 - Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint

CVE ID :CVE-2026-33638 Published : March 26, 2026, 8:52 p.m. | 35 minutes ago Description :Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/allusers` is mounted as a public endpoint and returns user records without authentication. This allows remote unauthenticated user enumeration and exposure of user profile metadata. A fix is available in v4.2.0. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
March 26, 2026