Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openclaw CRITICAL 9.1
CVE-2026-32064

OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Openclaw HIGH 7.1
CVE-2026-32057

OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that accepts cl…

Fix: 2026.2.25+
Fix from $1,950 2026-03-21
Openclaw MEDIUM 6.5
CVE-2026-32058

OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of p…

Fix: 2026.2.26+
Fix from $1,600 2026-03-21
Openclaw MEDIUM 6.5
CVE-2026-32065

OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval…

Fix: 2026.2.25+
Fix from $1,600 2026-03-21
Openclaw CRITICAL 9.8
CVE-2026-32052

OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidde…

Fix: 2026.2.24+
Fix from $2,300 2026-03-21
Openclaw HIGH 8.8
CVE-2026-32051

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to in…

Fix: 2026.3.1+
Fix from $1,950 2026-03-21
Openclaw HIGH 8.2
CVE-2026-32055

OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files out…

Fix: 2026.2.26+
Fix from $1,950 2026-03-21
Openclaw HIGH 7.8
CVE-2026-32054

OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local a…

Fix: 2026.2.25+
Fix from $1,950 2026-03-21
Openclaw MEDIUM 6.5
CVE-2026-32053

OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per pars…

Fix: 2026.2.23+
Fix from $1,600 2026-03-21
Openclaw CRITICAL 9.9
CVE-2026-32048

OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to …

Fix: 2026.3.1+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.8
CVE-2026-32046

OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by explo…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Openclaw CRITICAL 9.1
CVE-2026-32045

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and…

Fix: 2026.2.21+
Fix from $2,300 2026-03-21
Openclaw HIGH 7.5
CVE-2026-32049

OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple …

Fix: 2026.2.22+
Fix from $1,950 2026-03-21
Openclaw MEDIUM 5.3
CVE-2026-32050

OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized sender…

Fix: 2026.2.25+
Fix from $1,600 2026-03-21
Openclaw HIGH 8.8
CVE-2026-32042

OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pa…

Fix: 2026.2.25+
Fix from $1,950 2026-03-21
Openclaw HIGH 7.0
CVE-2026-32043

OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter…

Fix: 2026.2.25+
Fix from $1,950 2026-03-21
Openclaw MEDIUM 5.5
CVE-2026-32044

OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on…

Fix: 2026.3.2+
Fix from $1,600 2026-03-21
Openclaw CRITICAL 9.9
CVE-2026-22172

OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password…

Fix: 2026.3.12+
Fix from $2,300 2026-03-20
Openclaw HIGH 7.8
CVE-2026-32041

OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain…

Fix: 2026.3.1+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32039

OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers t…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 6.1
CVE-2026-32040

OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary …

Fix: 2026.2.23+
Fix from $1,600 2026-03-19
Openclaw CRITICAL 9.0
CVE-2026-32038

OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network…

Fix: 2026.2.24+
Fix from $2,300 2026-03-19
Openclaw HIGH 8.2
CVE-2026-32036

OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authenticatio…

Fix: 2026.2.6+
Fix from $1,950 2026-03-19
Openclaw HIGH 8.1
CVE-2026-32034

OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled an…

Fix: 2026.2.21+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.1
CVE-2026-32035

OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag t…

Fix: 2026.3.2+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32037

OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media…

Fix: 2026.2.22+
Fix from $1,600 2026-03-19
Openclaw HIGH 7.8
CVE-2026-32032

OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback that trusts the unvalidated SHE…

Fix: 2026.2.22+
Fix from $1,950 2026-03-19
Openclaw HIGH 7.5
CVE-2026-32030

OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths w…

Fix: 2026.2.19+
Fix from $1,950 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32031

OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authentication for plugin channel endpoin…

Fix: 2026.2.26+
Fix from $1,600 2026-03-19
Openclaw MEDIUM 6.5
CVE-2026-32033

OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundar…

Fix: 2026.2.24+
Fix from $1,600 2026-03-19