CRITICAL🇵🇱 Wersja polska

CVE-2026-43578

CVSS 9.1v4.0pub. 2026-05-06upd. 2026-05-07

OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted completion content to leave a run in a more privileged context than intended.

🤖 AI Analysis
How it works

The vulnerability results from an incomplete list of cases handled by the heartbeat owner's downgrade detection mechanism (CWE-184 — incomplete list of disallowed inputs). When a local asynchronous background process terminates, the completion event is not intercepted by the aforementioned mechanism. An attacker can provide untrusted completion content to such a process to force a running task to remain in a more privileged context than it should have after the operation completes.

Impact

An attacker can obtain a higher privilege level than they are entitled to, which combined with access to the local system can lead to unauthorized access to protected resources or further compromise of the system.

Mitigation & patch

OpenClaw should be updated to version 2026.4.10 or later. The patch is available in the project repository (commit 19a2e9ddb5a8a494abcba812bb11f51075026a27) and described in the vendor's official security advisory (GHSA-g375-h3v6-4873).

Who is affected

OpenClaw in versions from 2026.3.31 (inclusive) to 2026.4.10 (exclusive).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Openclaw

    APP
    Openclaw
    2026.3.31 – 2026.4.10 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2026-44109CRITICAL9.2PL ✓same product

OpenClaw — Auth Bypass w walidacji Feishu webhook umożliwia RCE

CVE-2026-43575CRITICAL9.2PL ✓same product

OpenClaw: Authentication Bypass w trasie pomocniczej sandbox noVNC

CVE-2026-43581CRITICAL9.0PL ✓same product

OpenClaw: ekspozycja Chrome DevTools Protocol poza sandbox

CVE-2026-43585CRITICAL9.2PL ✓same product

OpenClaw: ominięcie uwierzytelniania przez nieodświeżane tokeny bearer po rotacji SecretRef

CVE-2026-43534CRITICAL9.3PL ✓same product

OpenClaw: nieweryfikowane metadane hooków eskalowane do kontekstu systemowego