CVE-2026-56693

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent groups, container configurations, and destinations, escalating beyond their intended confinement boundary.
Configurations

No configuration.

History

23 Jun 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 16:17

Updated : 2026-06-23 17:58


NVD link : CVE-2026-56693

Mitre link : CVE-2026-56693

CVE.ORG link : CVE-2026-56693


JSON object : View

Products Affected

No product.

CWE
CWE-602

Client-Side Enforcement of Server-Side Security