CVE-2026-43575

critical
Published 2026-05-06 · Modified 2026-05-07
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive browser session.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/security/advisories/GHSA-92jp-89mq-4374

vendor Authored 2026-05-27

Vendor advisory: disclosure@vulncheck.com — https://github.com/openclaw/openclaw/commit/8dfbf3268bd224b7377d1ecca77a445100746085

Application impact

VendorProductVersionsFixed
openclawopenclaw{"startIncluding":"2026.2.21","endExcluding":"2026.4.10"}2026.4.10

References

CWEs

CWE-862

Verify integrity in audit chain (admin only). AS-IS.