CRITICAL🇵🇱 Wersja polska

CVE-2026-43575

CVSS 9.2v4.0pub. 2026-05-06upd. 2026-05-07

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive browser session.

🤖 AI Analysis
How it works

The noVNC auxiliary route in the sandbox module does not enforce bridge authentication (CWE-862 — missing authorization control). An attacker can directly access this route without any credentials. As a result, authentication data for the interactive browser session is exposed, enabling unauthorized takeover of the session.

Impact

An attacker can gain unauthorized access to an interactive browser session in the sandbox, taking full control of the session and potentially intercepting sensitive data processed within it.

Mitigation & patch

OpenClaw should be updated to version 2026.4.10 or later, in which the vulnerability has been patched. Details are available in the project's GitHub repository and in the published security advisory (GHSA-92jp-89mq-4374).

Who is affected

OpenClaw in versions from 2026.2.21 to 2026.4.9 (prior to version 2026.4.10)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openclaw

    APP
    Openclaw
    2026.2.21 – 2026.4.10 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-44109CRITICAL9.2PL ✓same product

OpenClaw — Auth Bypass w walidacji Feishu webhook umożliwia RCE

CVE-2026-43578CRITICAL9.1PL ✓same product

OpenClaw: privilege escalation przez pominięcie zdarzeń async exec w heartbeat

CVE-2026-43581CRITICAL9.0PL ✓same product

OpenClaw: ekspozycja Chrome DevTools Protocol poza sandbox

CVE-2026-43585CRITICAL9.2PL ✓same product

OpenClaw: ominięcie uwierzytelniania przez nieodświeżane tokeny bearer po rotacji SecretRef

CVE-2026-43534CRITICAL9.3PL ✓same product

OpenClaw: nieweryfikowane metadane hooków eskalowane do kontekstu systemowego