CVE-2026-15318: Incorrect Authorization in Sipeed PicoClaw
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Handler. This manipulation of the argument client_id causes incorrect authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The reported GitHub issue was closed automatically due to inactivity.
AI Analysis
Technical Summary
CVE-2026-15318 is an authorization weakness in Sipeed PicoClaw up to version 0.2.9. The vulnerability exists in the MQTT Channel Handler component, specifically in the handling of the client_id argument within pkg/channels/mqtt/mqtt.go. This flaw allows remote attackers to manipulate client_id values to bypass authorization checks, potentially gaining unauthorized access or privileges. The vulnerability has been publicly disclosed, but no official fix or patch has been released. The reported GitHub issue was closed without resolution due to inactivity.
Potential Impact
The vulnerability allows remote attackers to bypass authorization mechanisms by manipulating the client_id argument in the MQTT Channel Handler. This could lead to unauthorized access or actions within the affected system. The CVSS 4.0 score of 5.3 indicates a medium impact, reflecting limited privileges required and low complexity of attack but with some impact on confidentiality, integrity, or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch has been published and the vendor has not provided remediation details, users should monitor for updates from Sipeed. Until a fix is available, consider restricting network access to the MQTT service or implementing additional access controls to mitigate unauthorized client_id manipulation.
CVE-2026-15318: Incorrect Authorization in Sipeed PicoClaw
Description
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqtt.go of the component MQTT Channel Handler. This manipulation of the argument client_id causes incorrect authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The reported GitHub issue was closed automatically due to inactivity.
CVSS v4.0
Score 5.3medium
Affected software
pkg:github/sipeed/picoclawcpe:2.3:a:sipeed:picoclaw:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15318 is an authorization weakness in Sipeed PicoClaw up to version 0.2.9. The vulnerability exists in the MQTT Channel Handler component, specifically in the handling of the client_id argument within pkg/channels/mqtt/mqtt.go. This flaw allows remote attackers to manipulate client_id values to bypass authorization checks, potentially gaining unauthorized access or privileges. The vulnerability has been publicly disclosed, but no official fix or patch has been released. The reported GitHub issue was closed without resolution due to inactivity.
Potential Impact
The vulnerability allows remote attackers to bypass authorization mechanisms by manipulating the client_id argument in the MQTT Channel Handler. This could lead to unauthorized access or actions within the affected system. The CVSS 4.0 score of 5.3 indicates a medium impact, reflecting limited privileges required and low complexity of attack but with some impact on confidentiality, integrity, or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch has been published and the vendor has not provided remediation details, users should monitor for updates from Sipeed. Until a fix is available, consider restricting network access to the MQTT service or implementing additional access controls to mitigate unauthorized client_id manipulation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-07-09T18:07:35.019Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a504f5468715ace43b568ff
Added to database: 07/10/2026, 01:48:04 UTC
Last enriched: 07/17/2026, 09:42:49 UTC
Last updated: 08/23/2026, 10:52:07 UTC
Views: 123
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.