CVE-2026-43534Disclosure(openclaw / openclaw)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-14)
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-05-05: 3Mentions · 2026-05-06: 1Mentions · 2026-05-14: 4Patch / Workaround · 2026-05-05: 2Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-05: 3Technical Details · 2026-05-06: 1Technical Details · 2026-05-14: 305-0505-0605-14
Signal classification3 categories
Disclosure
450.0%
General
337.5%
Patch
112.5%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-053
Disclosure2Patch1
2026-05-061
Disclosure1
2026-05-144
Disclosure1General3
Full discourse8 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨 7 ثغرات خطيرة في OpenClaw! ⚠️ الثغرتين الأخطر ممكن تستغل بدون صلاحيات (Unauthenticated): (CVE-2026-43534) | تقييم 9.3 تخلي بيانات خارجية (External hook metadata) تعامل كأنها أوامر داخلية موثوقة للنظام و ثد تنتقل إلى سياق أعلى ثقة داخل الـ agent بدون تدخل من المستخدم. (CVE-2026-43566) | تقييم 9.1 المخترق يرسل (Webhook) من مصدر غير موثوق، ويتجاوز نظام الصلاحيات ليتنفذ الأمر كأنه من مالك النظام نفسه! ⚙️ الخمس ثغرات الباقية تحتاج صلاحيات منخفضة للاستغلال وكلها بتقييم 8.8: (CVE-2026-43571): إضافة خبيثة تنزل مكان الإضافة الرسمية بسبب خلل في ترتيب البحث وتتجاوز أدوات التحقق. (CVE-2026-43569): إضافة غير موثوقة تتفعل تلقائياً وقت الإعداد الأولي (Onboarding) بدون إذن المستخدم. (CVE-2026-43530): استخدام أدوات مجمعة مثل (busybox) يخلي المخترق يموّه الأوامر. النظام يوافق على أمر آمن ظاهرياً لكن اللي يتنفذ فعلياً أمر خبيث. (CVE-2026-42435): حقن متغيرات حساسة في الشل (مثل SHELLOPTS) على مستوى (argv) وتجاوز الفحص قبل التنفيذ. (CVE-2026-42434): هروب الوكيل من الـ Sandbox. 🛡️ حدّث فوراً لإصدار (2026.4.14).

    Post summary

    The post announces seven critical vulnerabilities in OpenClaw, outlining their technical mechanisms and severity ratings, and recommends updating to version 2026.4.14, but it does not provide proof of exploitation or active attack evidence.

    03016102.5K
    49.3K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-43534 — CVSS 9.1/10 █████████░ OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/jBFBMMeqRG

    Post summary

    The tweet discloses CVE-2026-43534, an input validation flaw in OpenClaw with a CVSS of 9.1, and indicates that a patch is now available.

    20010107
    26 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - OpenClaw Privilege Escalation (CVE-2026-43534) OpenClaw fails to validate input in hook metadata, allowing attackers to inject untrusted data as trusted system events - leading to privilege escalation. 👉 Remote, no authentication required 👉 CVSS 9.1 (Critical) 👉 Affects versions < 2026.4.10 👉 Update ASAP

    Post summary

    The post announces a critical privilege escalation flaw (CVE‑2026‑43534) in OpenClaw, highlighting remote, unauthenticated impact and urging an update.

    0002095
    237 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-43534 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry provides a critical advisory for CVE‑2026‑43534, including its CVSS score, but contains no proof‑of‑concept, exploit code, mitigation, or evidence of active exploitation.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-43534 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system…

    Post summary

    An input validation flaw in OpenClaw before 2026.4.10 enables external hook metadata to be enqueued as trusted system components, rated critical (CVSS 9.1).

    1000042
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CRITICAL: CVE-2026-43534 (CVSS 9.1) — multiple products. CVE: CVE-2026-43534 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The entry reports CVE‑2026‑43534 as a critical vulnerability with a CVSS score of 9.1 and a detailed vector, but it does not provide a PoC, exploit code, patch information, or evidence of active exploitation.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43534-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text references only a URL and hashtags, offering no specific information about the CVE beyond its mention.

    0000025
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43534 OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply … https://www.cve.org/CVERecord?id=CVE-2026-43534

    Post summary

    The post discloses an input validation vulnerability in OpenClaw that permits attackers to enqueue malicious hook metadata as trusted system events, without mentioning exploitation, a PoC, or a patch.

    00000142
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more