CVE-2026-10281
Deferred
Deferred - Pending Action
Authentication Bypass in Enderfga Claw-Orchestrator
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: VulDB
Description
Description
A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of the file src/embedded-server.ts of the component API Endpoint. This manipulation causes missing authentication. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 3.5.6 mitigates this issue. Patch name: d0b02a800aa0689d9428cc4cc170e0b6589fb2c3. The affected component should be upgraded.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| enderfga | claw-orchestrator | From 2.7.1 (inc) to 3.5.5 (inc) |
| enderfga | claw-orchestrator | 3.5.6 |
| enderfga | claw-orchestrator | to 3.5.5 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-287 | When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct. |
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |