OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.
References
Configurations
History
17 Jun 2026, 10:35
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
24 Mar 2026, 21:10
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01 - Patch | |
| References | () https://github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661 - Patch | |
| References | () https://github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph - Mitigation, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/openclaw-missing-vnc-authentication-in-sandbox-browser-novnc-observer - Third Party Advisory | |
| CPE | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| First Time |
Openclaw openclaw
Openclaw |
21 Mar 2026, 01:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-21 01:17
Updated : 2026-06-17 10:35
NVD link : CVE-2026-32064
Mitre link : CVE-2026-32064
CVE.ORG link : CVE-2026-32064
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-306
Missing Authentication for Critical Function
