CVE-2026-28455
- EPSS -
- Veröffentlicht 23.03.2026 21:36:01
- Zuletzt bearbeitet 23.03.2026 23:17:11
Rejected reason: This CVE ID has been rejected.
CVE-2026-27646
- EPSS 0.1%
- Veröffentlicht 23.03.2026 21:36:00
- Zuletzt bearbeitet 25.03.2026 15:16:39
OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to initialize host-side ACP runtime. Attackers can bypass sandbox restrictions by invoking the /acp spawn s...
CVE-2026-27183
- EPSS 0.11%
- Veröffentlicht 23.03.2026 21:35:59
- Zuletzt bearbeitet 25.03.2026 15:16:38
OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attackers to skip shell wrapper approval requirements. The approval classifier and execution planner apply di...
CVE-2026-22173
- EPSS -
- Veröffentlicht 23.03.2026 21:35:58
- Zuletzt bearbeitet 23.03.2026 23:17:11
Rejected reason: This CVE ID has been rejected.
CVE-2026-32899
- EPSS 0.2%
- Veröffentlicht 21.03.2026 00:42:35
- Zuletzt bearbeitet 24.03.2026 21:06:59
OpenClaw versions prior to 2026.2.25 fail to consistently apply sender-policy checks to reaction_* and pin_* non-message events before adding them to system-event context. Attackers can bypass configured DM policies and channel user allowlists to inj...
CVE-2026-32898
- EPSS 0.26%
- Veröffentlicht 21.03.2026 00:42:33
- Zuletzt bearbeitet 24.03.2026 21:07:15
OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted toolCall.kind metadata and permissive name heuristics. Attackers can bypass interactive approval pro...
CVE-2026-32896
- EPSS 0.25%
- Veröffentlicht 21.03.2026 00:42:32
- Zuletzt bearbeitet 17.09.2026 18:16:41
The BlueBubbles webhook handler in OpenClaw versions prior to 2026.2.21 contains a passwordless fallback authentication path that allows unauthenticated webhook events in certain reverse-proxy or local routing configurations. Attackers can bypass web...
CVE-2026-32897
- EPSS 0.26%
- Veröffentlicht 21.03.2026 00:42:32
- Zuletzt bearbeitet 24.03.2026 21:07:55
OpenClaw versions prior to 2026.2.22 reuse gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset, creating dual-use of authentication secrets ac...
CVE-2026-32895
- EPSS 0.18%
- Veröffentlicht 21.03.2026 00:42:31
- Zuletzt bearbeitet 23.03.2026 19:47:30
OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqueued. Attackers can bypass Slack DM allowlists and per-channel user allowlists by se...
CVE-2026-32065
- EPSS 0.29%
- Veröffentlicht 21.03.2026 00:42:30
- Zuletzt bearbeitet 24.03.2026 21:09:40
OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An attacker can ...