CVE-2026-17531

MEDIUM

unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization

Title source: cna
STIX 2.1

Description

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

References (6)

Core 6
Core References
Vdb Entry vdb-entry
VDB-383396 | unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization
https://vuldb.com/vuln/383396
Signature, Permissions Required signature permissions-required
VDB-383396 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/383396/cti
Third Party Advisory third-party-advisory
CVE-2026-17531 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-17531
Third Party Advisory third-party-advisory
Submit #862537 | unitedbyai DroidClaw 0.5.3 Authorization Bypass Through User-Controlled Key (CWE-639)
https://vuldb.com/submit/862537
Exploit exploit issue-tracking
https://github.com/unitedbyai/droidclaw/issues/18

Scores

CVSS v3 5.0
EPSS 0.0020
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-639
Status published
Products (4)
unitedbyai/droidclaw 0.5.0
unitedbyai/droidclaw 0.5.1
unitedbyai/droidclaw 0.5.2
unitedbyai/droidclaw 0.5.3
Published Jul 27, 2026
Tracked Since Jul 27, 2026