CVE-2026-32064

OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

17 Jun 2026, 10:35

Type Values Removed Values Added
Summary
  • (es) Las versiones de OpenClaw anteriores a 2026.2.21, en el punto de entrada del navegador sandbox, lanzan x11vnc sin autenticación para las sesiones de observador de noVNC, permitiendo acceso no autenticado a la interfaz VNC. Atacantes remotos en la interfaz de bucle invertido del host pueden conectarse al puerto noVNC expuesto para observar o interactuar con el navegador sandbox sin credenciales.

24 Mar 2026, 21:10

Type Values Removed Values Added
References () https://github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01 - () https://github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01 - Patch
References () https://github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661 - () https://github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph - () https://github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph - Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-missing-vnc-authentication-in-sandbox-browser-novnc-observer - () https://www.vulncheck.com/advisories/openclaw-missing-vnc-authentication-in-sandbox-browser-novnc-observer - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw

21 Mar 2026, 01:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 01:17

Updated : 2026-06-17 10:35


NVD link : CVE-2026-32064

Mitre link : CVE-2026-32064

CVE.ORG link : CVE-2026-32064


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-306

Missing Authentication for Critical Function