CVE-2026-16126

HIGH

zevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorization

Title source: cna
STIX 2.1

Description

A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authorization. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

References (8)

Core 8
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-379838 | zevorn rt-claw Swarm RPC Receiver swarm.c handle_rpc_request authorization
https://vuldb.com/vuln/379838
Signature, Permissions Required signature permissions-required
VDB-379838 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/379838/cti
Third Party Advisory third-party-advisory
CVE-2026-16126 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-16126
Third Party Advisory third-party-advisory
Submit #856870 | zevorn rt-claw unreleased post-v0.2.0 (36d128f) Incorrect Authorization (CWE-863)
https://vuldb.com/submit/856870
Third Party Advisory third-party-advisory
Submit #856871 | zevorn rt-claw unreleased post-v0.2.0 (36d128f) Improper Authorization (CWE-285) (Duplicate)
https://vuldb.com/submit/856871
Issue Tracking issue-tracking
https://github.com/zevorn/rt-claw/issues/135
Exploit exploit issue-tracking
https://github.com/zevorn/rt-claw/issues/137

Scores

CVSS v3 7.3
EPSS 0.0030
EPSS Percentile 22.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-285 CWE-863
Status published
Products (2)
zevorn/rt-claw 0.1
zevorn/rt-claw 0.2.0
Published Jul 18, 2026
Tracked Since Jul 18, 2026