CVE-2026-16123
A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP
CVSS
6.3
Medium
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Published: Jul 18, 2026 · Last modified: Jul 22, 2026 · CWE-862 · CWE-863
0.2%EPSS · 30 days0.4%
2026-08-202026-09-17
A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
- github.comhttps://github.com/nextlevelbuilder/goclaw/
- github.comhttps://github.com/nextlevelbuilder/goclaw/issues/1217
- github.comhttps://github.com/nextlevelbuilder/goclaw/issues/1217#issuecomment-4759982122
- vuldb.comhttps://vuldb.com/cve/CVE-2026-16123
- vuldb.comhttps://vuldb.com/submit/856857
- vuldb.comhttps://vuldb.com/vuln/379832
- vuldb.comhttps://vuldb.com/vuln/379832/cti
- vuldb.comhttps://vuldb.com/submit/856857
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-928934.3 MED—
——0A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An authenticated user whose host visibility is restricted by a permission filter can supply arbitrary host IDs within their organization and receive the full Ansible inventory for those hosts, including parameter values marked as hidden.1dCVE-2026-92611——
——0In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.1dCVE-2026-814393.7 LOW—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.1dCVE-2026-928944.3 MED—
——0A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authenticated user with the edit_ansible_variables permission can delete any LookupValue by ID, including override values for Ansible variables outside their permission filter scope and override values belonging to Puppet smart class parameters.1dCVE-2026-784263.7 LOW8.5%
——3The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equivalent spelling of the RSA signature field until the token validity expires.1dCVE-2026-878314.3 MED4.7%
——1The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.1d