---
id: CVE-2026-16081
title: A vulnerability was determined in Sipeed PicoClaw up to 0.2.9
summary: >-
  A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected
  element is an unknown function of the file web/backend/api/auth.go. Executing
  a manipulation can lead to cross-site request forgery. The attack can be
  launched r…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
  - CWE-862
published: '2026-07-18'
updated: '2026-07-18'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16081'
references:
  - url: 'https://github.com/sipeed/picoclaw/'
    label: cna@vuldb.com
  - url: >-
      https://github.com/sipeed/picoclaw/commit/4b0229351678f479429b8d8b19207757266f246b
    label: cna@vuldb.com
  - url: 'https://github.com/sipeed/picoclaw/issues/3072'
    label: cna@vuldb.com
  - url: 'https://github.com/sipeed/picoclaw/pull/3160'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-16081'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/852943'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/379793'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/379793/cti'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00241
epssPercentile: 0.13579
ingestedAt: '2026-07-18T22:25:39.686Z'
---

## Overview

A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 4b0229351678f479429b8d8b19207757266f246b. Applying a patch is advised to resolve this issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
