CVE-2026-33638 addresses an unauthenticated user enumeration vulnerability in the Ech0 open-source publishing platform, affecting versions prior to 4.2.0. This flaw allows remote attackers to access the `/api/allusers` endpoint without authentication, exposing user profile metadata. Rated with a CVSS score of 5.3 (Medium), the vulnerability has a low attack complexity and can be exploited over the network without user interaction, resulting in a low impact on confidentiality. Currently, there is no evidence of active exploitation, nor is public exploit code available in common repositories, indicating low community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.0CPE matchmatch criteria | cpe:2.3:a:ech0:ech0:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.