What is CVE-2026-17531?
This vulnerability in unitedbyai droidclaw up to version 0.5.3 allows authorization bypass via the Unsigned Scheduled Callback in server/src/routes/goals.ts. Remote exploitation is possible, potentially leading to unauthorized access. Users should update to the latest version immediately.
Azərbaycanca: Bu zəiflik unitedbyai droidclaw-ın 0.5.3 versiyasına qədər olan versiyalarında server/src/routes/goals.ts faylındakı Unsigned Scheduled Callback komponentində avtorizasiya bypass imkanı yaradır. Uzaqdan istismar mümkündür, bu da icazəsiz girişlərə səbəb ola bilər. İstifadəçilərə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of unitedbyai droidclaw are affected by CVE-2026-17531?
This vulnerability affects all versions of unitedbyai droidclaw up to version 0.5.3.
What is the potential impact of exploiting CVE-2026-17531?
Remote exploitation is possible, potentially leading to unauthorized access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.