CVE-2026-17434
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/reques
CVSS
6.3
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 26 jul 2026 · Última mod.: 26 jul 2026 · CWE-266 · CWE-285
Sin historial EPSS suficiente todavía.
A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. This patch is called e5b928783d5c485637565eb07d2967922dfbf8d8. A patch should be applied to remediate this issue.
- github.comhttps://github.com/nanocoai/nanoclaw/
- github.comhttps://github.com/nanocoai/nanoclaw/commit/e5b928783d5c485637565eb07d2967922dfbf8d8
- github.comhttps://github.com/nanocoai/nanoclaw/issues/2762
- github.comhttps://github.com/nanocoai/nanoclaw/pull/2998
- vuldb.comhttps://vuldb.com/cve/CVE-2026-17434
- vuldb.comhttps://vuldb.com/submit/862451
- vuldb.comhttps://vuldb.com/vuln/383075
- vuldb.comhttps://vuldb.com/vuln/383075/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-174335.3 MED—
——0A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. Performing a manipulation results in improper authorization. The attack needs to be approached locally. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.15hCVE-2026-174325.0 MED—
——0A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitation appears to be difficult. The exploit is now public and may be used. The patch is identified as 490c486ff65b766d9de0fe0e6f26e1778aaa8fb3. Applying a patch is advised to resolve this issue.17hCVE-2026-628359.3 CRÍ60.3%
——18Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.2dCVE-2026-561609.1 CRÍ47.5%
——14Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.2dCVE-2026-167646.3 MED14.4%
——4A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of the component API/Web. Such manipulation of the argument is_staff leads to improper privilege management. The attack may be performed from remote. The exploit is publicly available and might be used. Upgrading to version 2.58.3 and 3.0.0 is capable of addressing this issue. The name of the patch is 68a272f299d096249fd3ba9c2676bf69012857bf. It is advisable to upgrade the affected component. 2.59.0 was not intended to be released and has been removed.2dCVE-2026-619519.8 CRÍ24.5%
——7Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.3d