PT-2026-60997 · Sipeed · Picoclaw

·

CVE-2026-16198

·

Published

2026-07-18

·

Updated

2026-07-19

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Sipeed PicoClaw versions prior to 0.3.0
Description An authentication bypass exists in the First Run Setup component within the web/backend/middleware/access control.go file. A remote attacker can bypass authentication using an alternate channel by manipulating the allowed cidrs argument. CIDR (Classless Inter-Domain Routing) is a method for allocating IP addresses and routing IP packets.
Recommendations Apply patch 017601354be38cb027ff3ffb01aed79bd5d12610 to resolve the issue.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16198

Affected Products

Picoclaw