Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6635

24
FAUCET Score

BRIEFING NOTE: CVE-2026-6635 Rowboat Labs' rowboat tool up to version 0.1.67 contains an authentication bypass vulnerability in the tools_webhook component. The flaw exists in the tool_call function of apps/experimental/tools_webhook/app.py, where improper validation of the X-Tools-JWE argument allows attackers to circumvent authentication controls. The vulnerability carries a HIGH severity rating of 7.3 CVSS with a network-based attack vector requiring no authentication, low complexity, and no user interaction. The impact is moderate, affecting confidentiality, integrity, and availability with consequences limited to the vulnerable application scope. This positions it as a significant remote exploitation risk that could lead to unauthorized access and data manipulation. The exploit has been publicly disclosed, and while there is no current evidence of active exploitation in the wild, the vendor has not responded to early disclosure notifications. The FAUCET risk score of 37.0 and presence on the active Hot List suggest ongoing community attention. Organizations running affected versions should prioritize patching beyond version 0.1.67 and implement access controls to restrict unauthenticated tool_webhook requests.

Impacted Technologies

VendorProductVersion(s)CPE
RowboatlabsRowboat
0.1.0, 0.1.1, 0.1.10, 0.1.11, 0.1.12, 0.1.13, 0.1.14, 0.1.15, 0.1.16, 0.1.17, 0.1.18, 0.1.19, 0.1.2, 0.1.20, 0.1.21, 0.1.22, 0.1.23, 0.1.24, 0.1.25, 0.1.26, 0.1.27, 0.1.28, 0.1.29, 0.1.3, 0.1.30, 0.1.31, 0.1.32, 0.1.33, 0.1.34, 0.1.35, 0.1.36, 0.1.37, 0.1.38, 0.1.39, 0.1.4, 0.1.40, 0.1.41, 0.1.42, 0.1.43, 0.1.44, 0.1.45, 0.1.46, 0.1.47, 0.1.48, 0.1.49, 0.1.5, 0.1.50, 0.1.51, 0.1.52, 0.1.53, 0.1.54, 0.1.55, 0.1.56, 0.1.57, 0.1.58, 0.1.59, 0.1.6, 0.1.60, 0.1.61, 0.1.62, 0.1.63, 0.1.64, 0.1.65, 0.1.66, 0.1.67, 0.1.7, 0.1.8, 0.1.9CNA affected

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
37.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 16th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / Dave-gilmore-aus/security-advisories/blob/main/rowbat-advisory
vuldb.com / submit/793433
vuldb.com / vuln/358269
vuldb.com / vuln/358269/cti