CVE-2026-16015

MEDIUM

poco-ai poco-claw executor_manager API tasks.py create_task missing authentication

Title source: cna
STIX 2.1

Description

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.5.7 is able to resolve this issue. This patch is called 67fcc88505c57f77d3fcf04eb5b89425b10cbf48. It is recommended to upgrade the affected component.

References (13)

Core 13
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-379757 | poco-ai poco-claw executor_manager API tasks.py create_task missing authentication
https://vuldb.com/vuln/379757
Signature, Permissions Required signature permissions-required
VDB-379757 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/379757/cti
Third Party Advisory third-party-advisory
CVE-2026-16015 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16015
Third Party Advisory third-party-advisory
Submit #856812 | poco-ai poco-agent 0.5.4 Missing Authentication for Critical Function (CWE-306)
https://vuldb.com/submit/856812
Third Party Advisory third-party-advisory
Submit #856813 | poco-ai poco-agent 0.5.4 Missing Authentication for Critical Function (CWE-306) (Duplicate)
https://vuldb.com/submit/856813
Third Party Advisory third-party-advisory
Submit #856815 | poco-ai poco-agent 0.5.4 Missing Authentication for Critical Function (CWE-306) (Duplicate)
https://vuldb.com/submit/856815
Third Party Advisory third-party-advisory
Submit #856816 | poco-ai poco-agent 0.5.4 Authorization Bypass Through User-Controlled Key (CWE-639) (Duplicate)
https://vuldb.com/submit/856816
Exploit exploit issue-tracking
https://github.com/poco-ai/poco-claw/issues/136
Patch exploit issue-tracking patch
https://github.com/poco-ai/poco-claw/pull/135
Exploit exploit issue-tracking
https://github.com/poco-ai/poco-claw/issues/137
Exploit exploit product
https://github.com/poco-ai/poco-claw/

Scores

CVSS v3 6.3
EPSS 0.0038
EPSS Percentile 31.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-287 CWE-306
Status published
Products (6)
poco-ai/poco-claw 0.5.0
poco-ai/poco-claw 0.5.1
poco-ai/poco-claw 0.5.2
poco-ai/poco-claw 0.5.3
poco-ai/poco-claw 0.5.4
poco-ai/poco-claw 0.5.7
Published Jul 17, 2026
Tracked Since Jul 17, 2026