CVE-2026-16015

Source
https://cve.org/CVERecord?id=CVE-2026-16015
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16015.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16015
Published
2026-07-17T13:15:12.605Z
Modified
2026-08-12T03:51:44.320899513Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
Details

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function createtask of the file executormanager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.5.7 is able to resolve this issue. This patch is called 67fcc88505c57f77d3fcf04eb5b89425b10cbf48. It is recommended to upgrade the affected component.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16015.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-287",
        "CWE-306"
    ]
}
References

Affected packages

Git / github.com/poco-ai/poco-claw

Affected ranges

Type
GIT
Repo
https://github.com/poco-ai/poco-claw
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0.5.0"
        },
        {
            "last_affected": "0.5.0"
        },
        {
            "introduced": "0.5.1"
        },
        {
            "last_affected": "0.5.1"
        },
        {
            "introduced": "0.5.2"
        },
        {
            "last_affected": "0.5.2"
        },
        {
            "introduced": "0.5.3"
        },
        {
            "last_affected": "0.5.3"
        },
        {
            "introduced": "0.5.4"
        },
        {
            "last_affected": "0.5.4"
        }
    ]
}

Affected versions

0.*
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
v0.*
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.5.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16015.json"