RapidClaw[verified]@ClawRapidDisclosure
The text reports a high‑severity vulnerability (CVE-2026-22172) that allows low‑privilege users to acquire admin privileges via WebSocket handshake, but it provides no PoC, exploit code, or patch information.
Shin0221 🇯🇵 Indie Hacker🦞[verified]@0xShin0221Patch
OpenClaw released a patch for CVE‑2026‑22172, a high‑severity flaw allowing websocket clients to impersonate administrators, as part of nine new CVEs disclosed over four days.
Orizon[verified]@OrizonCyberPatch
OpenClaw versions prior to 2026.3.12 suffer from a critical authorization bypass via the WebSocket connect path (CVSS 9.9/10). A patch has already been released.
Agentic Yield[verified]@AgenticYieldDisclosure
An advisory for CVE‑2026‑22172 in OpenClaw outlines a critical flaw that lets shared‑token connections self‑declare elevated scopes, urging users to verify their version, without mentioning exploits or additional mitigation details.
Guang Gong@oldfresherGeneral
The tweet contrasts authentication requirements across two CVEs, noting inconsistent acceptance standards, but provides no evidence of PoC, exploit, or patch availability.
Kevin Poireault@kpoireaultDisclosure
The post shares links to advisories and the CVE JSON for CVE-2026-22172, indicating the vulnerability has been disclosed but lacks details on PoC, exploit, or active exploitation.
Kevin Poireault@kpoireaultPatch
The tweet reports a critical vulnerability (CVE-2026-22172) affecting OpenClaw prior to version 2026.3.12 and announces that the issue will be fixed in OpenClaw 2026.3.12.
PulsePatch.io@pulsepatchioDisclosure
The post announces a critical OpenClaw vulnerability (CVE‑2026‑22172) that lets WebSocket shared‑auth connections grant themselves higher privileges, urging users to audit their deployments.