CVE-2026-16195

Source
https://cve.org/CVERecord?id=CVE-2026-16195
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16195.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-16195
Published
2026-07-18T22:30:10.281Z
Modified
2026-07-22T05:29:55.202058081Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Sipeed PicoClaw Group Message wecom.go dispatchIncoming authorization
Details

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The reported GitHub issue was closed automatically due to inactivity.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16195.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-285",
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/sipeed/picoclaw

Affected ranges

Type
GIT
Repo
https://github.com/sipeed/picoclaw
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0.2.0"
        },
        {
            "last_affected": "0.2.0"
        },
        {
            "introduced": "0.2.1"
        },
        {
            "last_affected": "0.2.1"
        },
        {
            "introduced": "0.2.2"
        },
        {
            "last_affected": "0.2.2"
        },
        {
            "introduced": "0.2.3"
        },
        {
            "last_affected": "0.2.3"
        },
        {
            "introduced": "0.2.4"
        },
        {
            "last_affected": "0.2.4"
        },
        {
            "introduced": "0.2.5"
        },
        {
            "last_affected": "0.2.5"
        },
        {
            "introduced": "0.2.6"
        },
        {
            "last_affected": "0.2.6"
        },
        {
            "introduced": "0.2.7"
        },
        {
            "last_affected": "0.2.7"
        },
        {
            "introduced": "0.2.8"
        },
        {
            "last_affected": "0.2.8"
        },
        {
            "introduced": "0.2.9"
        },
        {
            "last_affected": "0.2.9"
        }
    ]
}

Affected versions

0.*
0.2.0
0.2.1
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9
v0.*
v0.2.0
v0.2.1
v0.2.2
v0.2.2-nightly.20260312.6612ca09
v0.2.3
v0.2.4
v0.2.5
v0.2.6
v0.2.7
v0.2.8
v0.2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-16195.json"