PT-2026-99275 · Clawhub · Clawhub
CVE-2026-100604
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
ClawHub versions prior to 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650
Description
An incorrect authorization issue exists in the application backend where organization-owned skills retain the
ownerUserId of the original publisher. Because transfer and lifecycle authorization checks trust this historical user before verifying current organization privileges, an authenticated user who originally published a skill can transfer, delete, or restore it. This allows the user to maintain control over the skill's trusted name and history even after their organization privileges have been revoked or downgraded.Recommendations
Update to revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650 or a later descendant.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clawhub