CVE-2026-16081

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 4b0229351678f479429b8d8b19207757266f246b. Applying a patch is advised to resolve this issue.
Configurations

No configuration.

History

18 Jul 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-18 08:16

Updated : 2026-07-20 15:16


NVD link : CVE-2026-16081

Mitre link : CVE-2026-16081

CVE.ORG link : CVE-2026-16081


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization