CVE-2026-16119

Severity CVSS v4.0:
LOW
Type:
CWE-285 Improper Authorization
Publication date:
18/07/2026
Last modified:
21/07/2026

Description

A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.