CVE-2026-16122EPSS p21.2%

CVE-2026-16122CVE-2026-16122

Description

A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may be used for attacks.

Scoring

CVSS 4.3 ()
VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
EPSS0.31% probability of exploitation · percentile 21.2% · 2026-10-05T12:00:23Z
Last modified2026-07-20
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.