CVE-2026-15319
HIGHSipeed PicoClaw Launcher access_control.go IPAllowlist access control
Title source: cnaDescription
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 3126. A patch should be applied to remediate this issue.
References (7)
Core 7
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-377259 | Sipeed PicoClaw Launcher access_control.go IPAllowlist access control
https://vuldb.com/vuln/377259
Signature, Permissions Required signature
permissions-required
VDB-377259 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/377259/cti
Exploit exploit
issue-tracking
https://github.com/sipeed/picoclaw/issues/3069
Patch issue-tracking
patch
https://github.com/sipeed/picoclaw/pull/3126
Product product
https://github.com/sipeed/picoclaw/
Third Party Advisory third-party-advisory
CVE-2026-15319 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15319
Third Party Advisory third-party-advisory
Submit #852884 | Sipeed PicoClaw Unreleased main branch after launcher introduction commit `e55b3b7a8d0b1ea1522da08fd46155ee4f58b794` and before a fix is merged Improper Access Control (CWE-284)
https://vuldb.com/submit/852884
Scores
CVSS v3
7.3
EPSS
0.0032
EPSS Percentile
24.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-266
CWE-284
Status
published
Products (10)
Sipeed/PicoClaw
0.2.0
Sipeed/PicoClaw
0.2.1
Sipeed/PicoClaw
0.2.2
Sipeed/PicoClaw
0.2.3
Sipeed/PicoClaw
0.2.4
Sipeed/PicoClaw
0.2.5
Sipeed/PicoClaw
0.2.6
Sipeed/PicoClaw
0.2.7
Sipeed/PicoClaw
0.2.8
Sipeed/PicoClaw
0.2.9
Published
Jul 10, 2026
Tracked Since
Jul 10, 2026