CVE-2026-43566Disclosure(openclaw / openclaw)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. Attackers can exploit this by sending untrusted webhook wake events to preserve owner-like execution context when the run should have been downgraded.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-06); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-05: 1Mentions · 2026-05-06: 2Mentions · 2026-05-14: 2Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-14: 105-0505-0605-14
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-051
Disclosure1
2026-05-062
Disclosure1Patch1
2026-05-142
Disclosure1General1
Full discourse5 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🚨 7 ثغرات خطيرة في OpenClaw! ⚠️ الثغرتين الأخطر ممكن تستغل بدون صلاحيات (Unauthenticated): (CVE-2026-43534) | تقييم 9.3 تخلي بيانات خارجية (External hook metadata) تعامل كأنها أوامر داخلية موثوقة للنظام و ثد تنتقل إلى سياق أعلى ثقة داخل الـ agent بدون تدخل من المستخدم. (CVE-2026-43566) | تقييم 9.1 المخترق يرسل (Webhook) من مصدر غير موثوق، ويتجاوز نظام الصلاحيات ليتنفذ الأمر كأنه من مالك النظام نفسه! ⚙️ الخمس ثغرات الباقية تحتاج صلاحيات منخفضة للاستغلال وكلها بتقييم 8.8: (CVE-2026-43571): إضافة خبيثة تنزل مكان الإضافة الرسمية بسبب خلل في ترتيب البحث وتتجاوز أدوات التحقق. (CVE-2026-43569): إضافة غير موثوقة تتفعل تلقائياً وقت الإعداد الأولي (Onboarding) بدون إذن المستخدم. (CVE-2026-43530): استخدام أدوات مجمعة مثل (busybox) يخلي المخترق يموّه الأوامر. النظام يوافق على أمر آمن ظاهرياً لكن اللي يتنفذ فعلياً أمر خبيث. (CVE-2026-42435): حقن متغيرات حساسة في الشل (مثل SHELLOPTS) على مستوى (argv) وتجاوز الفحص قبل التنفيذ. (CVE-2026-42434): هروب الوكيل من الـ Sandbox. 🛡️ حدّث فوراً لإصدار (2026.4.14).

    Post summary

    The post lists seven severe (CVSS 8.8‑9.3) OpenClaw CVEs, outlines technical vectors such as unauthenticated privilege escalation and malicious plugin injection, and urges an immediate upgrade to version 2026.4.14 to mitigate the risks.

    03016102.5K
    49.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-43566 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    Advisory announces CVE-2026-43566 as a critical vulnerability with CVSS 9.1; no PoC, exploit, or patch information is provided.

    1000043
    210 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerabilities discovered in #OpenClaw. #CVE-2026-43566 (CVSS: 9.1). Attackers can escalate untrusted input into higher-trust agent context to via untrusted webhook wake events. More info: https://github.com/openclaw/openclaw/security #Patch #Patch #Patch

    Post summary

    The post discloses CVE‑2026‑43566 in OpenClaw, noting a high‑severity vulnerability that allows attackers to elevate privileges through webhook events, but it offers no PoC, exploit details, or patch information.

    01000224
    7.2K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43566-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post is a bare link to an advisory for CVE-2026-43566 with no other details provided.

    0000025
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43566 OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untr… https://www.cve.org/CVERecord?id=CVE-2026-43566

    Post summary

    The text announces CVE-2026-43566 in OpenClaw, noting a privilege escalation flaw but offers no PoC, exploit, active exploitation claims, patch information, or detailed technical data.

    00000158
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more