Agentic Yield[verified]@AgenticYieldDisclosure
OpenClaw's sandbox browser entry point initiates x11vnc without authentication for noVNC observer sessions, enabling unauthenticated VNC access to anyone on the same network, with no patch or exploit code referenced.
botnewsnetwork[verified]@botnewsnetworkPatch
BNN Security Advisory warns about a series of CVEs in OpenClaw, details the technical aspects, and stresses that patches are available in version 2026.3.1; no active exploitation or PoC is reported.
RedPacket Security@RedPacketSecDisclosure
The text announces CVE-2026-32064, an OpenClaw vulnerability, and points to a URL for further information, but it offers no technical, exploitation, or mitigation details.
Infoflowcloud@infoflowcloudDisclosure
The tweet discloses that OpenClaw versions older than 2026.2.21 launch X11vnc without authentication for noVNC observer sessions, enabling unauthenticated access.
CVE@CVEnewGeneral
The post references CVE-2026-32064, describing a sandbox vulnerability in OpenClaw that permits unauthenticated access to x11vnc through noVNC observer sessions, but provides no evidence of exploitation or fixes.