SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-15622

MEDIUM · CVSS 5.3 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A vulnerability exists in the Workspace API of poco-ai poco-claw versions up to 0.5.4, where manipulation of the user_id argument can result in an authorization bypass, allowing unauthorized access to sensitive resources. This flaw can be exploited remotely, making it critical for organizations using affected versions to prioritize patching to mitigate potential security risks. Users of the affected component should upgrade to the patched version to safeguard against this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit poc

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15622
Severity
MEDIUM
CVSS
5.3
EPSS
0.35%

Original NVD Description

A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack may be launched remotely. The exploit has been published and may be used. This patch is called 67fcc88505c57f77d3fcf04eb5b89425b10cbf48. Upgrading the affected component is recommended.