CVE-2026-10281 Details
Description
A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.5.6 mitigates this issue. Patch name: d0b02a800aa0689d9428cc4cc170e0b6589fb2c3. The affected component should be upgraded.
A vulnerability exists in Enderfga Claw-Orchestrator versions prior to 3.5.6, specifically within the embedded server component of the API endpoint. The issue arises because the server does not require authentication by default, allowing unauthorized access to critical functions. This vulnerability can be exploited remotely if the server is configured to accept external connections.
Upgrade to Enderfga Claw-Orchestrator version 3.5.6 or later, which requires authentication by default on all endpoints except '/health'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 1, 2026CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Enderfga/claw-orchestrator/ | [email protected] | ProductSource CodeVendor |
| https://github.com/Enderfga/claw-orchestrator/commit/d0b02a800aa0689d9428cc4cc170e0b6589fb2c3 | [email protected] | Source CodeVendor |
| https://github.com/Enderfga/claw-orchestrator/issues/61 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Enderfga/claw-orchestrator/releases/tag/v3.5.6 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-10281 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/825429 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/367574 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/367574/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Enderfga claw-orchestrator | <= 3.5.5 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |
Volerion