CVE-2026-16195 - Sipeed PicoClaw Group Message Authorization Flaw
CVE-2026-16195 - Sipeed PicoClaw Group Message Authorization Flaw
A critical security flaw has been discovered in Sipeed PicoClaw up to version 0.2.9. This issue affects the function dispatchIncoming in the file pkg/channels/wecom/wecom.go of the Group Message Handler component. The manipulation results in incorrect authorization, making it possible to launch attacks remotely. 🚨
The vulnerability is identified as CVE-2026-16195. The affected vendor is Sipeed, and the impacted product is picoclaw. In total, one vendor and one product are affected. The vulnerability was published on July 18, 2026, and confirmed as remotely exploitable. 🔒
CVSS Scores
The Common Vulnerability Scoring System (CVSS) provides various scores for CVE-2026-16195:
- CVSS 2.0 Score: 6.5 (MEDIUM)
- Exploitability Score: 8.0
Impact Score: 6.4
- CVSS 3.1 Score: 6.3 (MEDIUM)
- Exploitability Score: 2.8
Impact Score: 3.4
- CVSS 4.0 Score: 2.1 (LOW)
Recommended Actions
To address these authorization flaws, it is recommended to update Sipeed PicoClaw to version 0.2.9 or later. Specific mitigation steps include applying security patches for the Group Message Handler component. Additionally, organizations should review and correct authorization logic in wecom.go. 🔧
For more details, you can read the complete article here: Read full article