SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17531

MEDIUM · CVSS 5 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

A vulnerability exists in the Unsigned Scheduled Callback functionality of the unitedbyai droidclaw component, allowing for potential authorization bypass. Although the exploitation is complex and challenging, remote attackers could leverage publicly available exploits to gain unauthorized access. Organizations using versions up to 0.5.3 should prioritize patching this issue to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-17531
Severity
MEDIUM
CVSS
5
EPSS
0.20%

Original NVD Description

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.