CVE-2026-7505Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.9.0 mitigates this issue. Patch name: 406022e79f4a18b3070a446712080571eff11e30. You should upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-30); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-30: 2Mentions · 2026-05-01: 1Technical Details · 2026-05-01: 104-3005-01
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-302
Disclosure1General1
2026-05-011
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-7505 A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes im… https://www.cve.org/CVERecord?id=CVE-2026-7505

    Post summary

    The post announces a flaw in GoClaw and GoClaw Lite affecting an RPC handler, but provides no technical details, exploit evidence, or mitigation information.

    00010151
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7505 Remote Code Execution via Improper Authorization in nextlevelbuilder GoClaw 3.8.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7505

    Post summary

    CVE-2026-7505 exposes a remote code execution flaw via improper authorization in nextlevelbuilder GoClaw 3.8.5, with no PoC, exploit, or patch information provided.

    0000040
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7505 A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes im… https://www.cve.org/CVERecord?id=CVE-2026-7505 ----- Traducción: Se ha encontrado … http://infoflow.cloud`

    Post summary

    A new vulnerability (CVE-2026-7505) has been reported in Nextlevelbuilder GoClaw and GoClaw Lite affecting an unknown function within the RPC Handler, but no PoC, exploit, patch, or evidence of active exploitation is mentioned.

    0000016
    75 followersView on X

Explore more