Improper Authorization in nextlevelbuilder GoClaw Affects Remote Access
CVE-2026-10218
Key Information:
- Vendor
Nextlevelbuilder
- Status
- Vendor
- CVE Published:
- 1 June 2026
Badges
What is CVE-2026-10218?
A vulnerability exists in nextlevelbuilder's GoClaw, specifically in the authentication function within the internal HTTP request handler. This flaw, found in versions up to 3.11.3, enables attackers to manipulate authorization processes remotely, potentially leading to unauthorized access. The issue has been publicly disclosed, making it imperative for users to review their security settings and apply necessary updates to mitigate risks associated with this vulnerability.
Affected Version(s)
GoClaw 3.11.0
GoClaw 3.11.1
GoClaw 3.11.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
