Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 21, 2026
nextlevelbuilder GoClaw WebSocket Approval Endpoint exec_approval.go RequestApproval authorization
CVE-2026-16119
Description
A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Affected products
1- Range: <=3.13.2
Patches
Vulnerability mechanics
References
6- github.com/nextlevelbuilder/goclaw/issues/1212mitreexploitissue-tracking
- vuldb.com/cve/CVE-2026-16119mitrethird-party-advisory
- vuldb.com/submit/856825mitrethird-party-advisory
- github.com/nextlevelbuilder/goclaw/issues/1212mitreissue-tracking
- vuldb.com/vuln/379828mitrevdb-entrytechnical-description
- vuldb.com/vuln/379828/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.