Junglewise Threat Intelligence

CVE-2026-16015: poco-ai poco-claw missing authentication in executor_manager API

CVE-2026-16015 · Severity: medium · CVSS 6.3 · Published 2026-07-17

Technologies: Poco-Ai Claw. Vendors: Poco-Ai.

Executive brief

Poco-claw is an AI agent platform used for team collaboration and automated task execution. A security flaw in its task management component allows unauthorized users to create tasks while pretending to be someone else, including administrators. This could allow an attacker to steal sensitive system secrets or gain unauthorized access to private data by impersonating high-privileged accounts.

Technical details

A missing authentication vulnerability exists in the `create_task` function within `executor_manager/app/api/v1/tasks.py`. The API endpoint `POST /api/v1/tasks` accepts a `user_id` directly from the request body without verifying the caller's identity. This untrusted `user_id` is subsequently used to populate the `X-User-Id` internal header when communicating with the backend. An attacker can exploit this to impersonate an administrator, causing the backend to release 'admins_only' system environment variables and secrets during task execution. The issue is resolved in version 0.5.7 by requiring internal tokens for manager APIs.

Affected products

  • poco-ai poco-claw up to 0.5.4

Timeline

  • 2026-06-11: patched: Fix commit 67fcc88505c57f77d3fcf04eb5b89425b10cbf48 applied
  • 2026-07-17: disclosed: CVE-2026-16015 published

References

Related threats