PULSE
LIVE34signals / 24h
FEED
ransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Servicesransomqilin reclama a Universitatea de Vest „Vasile Goldiș” din Arad · RO · Educationransomm3rx reclama a hydraulic-components.net · DE · Manufacturingransomm3rx reclama a createinfor.pt · PT · Professional Servicesransomm3rx reclama a servicebypremier.com · US · Professional Servicesransomexfilsquad reclama a Analog Devices · US · Technologyransomexfilsquad reclama a Bonava · SE · Manufacturingransomexfilsquad reclama a City of Atlanta · US · Government & Defenseransomexfilsquad reclama a City of Houston · US · Government & Defenseransomexfilsquad reclama a Viavi Solutions · US · Technologyransomexfilsquad reclama a Newcastle University · GB · Educationransomexfilsquad reclama a District of Columbia Public Schools · US · Educationransomexfilsquad reclama a Zenith Bank Plc · NG · Financial Servicesransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Servicesransomqilin reclama a Universitatea de Vest „Vasile Goldiș” din Arad · RO · Educationransomm3rx reclama a hydraulic-components.net · DE · Manufacturingransomm3rx reclama a createinfor.pt · PT · Professional Servicesransomm3rx reclama a servicebypremier.com · US · Professional Servicesransomexfilsquad reclama a Analog Devices · US · Technologyransomexfilsquad reclama a Bonava · SE · Manufacturingransomexfilsquad reclama a City of Atlanta · US · Government & Defenseransomexfilsquad reclama a City of Houston · US · Government & Defenseransomexfilsquad reclama a Viavi Solutions · US · Technologyransomexfilsquad reclama a Newcastle University · GB · Educationransomexfilsquad reclama a District of Columbia Public Schools · US · Educationransomexfilsquad reclama a Zenith Bank Plc · NG · Financial Services
← All CVEs
CVE WatchJul 26, 2026

CVE-2026-17434

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/reques

CVSS

6.3

Medium

EPSS

KEV

Exploit Today

0

0-100

Published: Jul 26, 2026 · Last modified: Jul 26, 2026 · CWE-266 · CWE-285

EPSS · 30d

Not enough EPSS history yet.

Technical description

A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-174335.3 MED
0A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to be approached locally. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.14h
CVE-2026-174325.0 MED
0A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is identified as 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Applying a patch is advised to resolve this issue.16h
CVE-2026-628359.3 CRI
60.3%
18Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.2d
CVE-2026-561609.1 CRI
47.5%
14Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.1d
CVE-2026-167646.3 MED
14.4%
4A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.2d
CVE-2026-619519.8 CRI
24.5%
7Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.3d