CVE-2026-43578Disclosure(openclaw / openclaw)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted completion content to leave a run in a more privileged context than intended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-14)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-07: 1Mentions · 2026-05-14: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-14: 105-0605-0705-14
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-071
Disclosure1
2026-05-142
General2
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-43578 CVSS: 9.1 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The tweet only lists CVE-2026-43578 with a CVSS score of 9.1 and marks it as critical, offering no further technical, exploit, or patch details.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43578-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The content only includes a URL and generic hashtags, offering no specific information about the CVE, proof of concept, patches, or exploitation activity.

    0000015
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43578 OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec… https://www.cve.org/CVERecord?id=CVE-2026-43578

    Post summary

    The statement discloses a privilege escalation flaw in OpenClaw versions 2026.3.31 to before 2026.4.10, where heartbeat owner downgrade detection is bypassed during local background async execution; no PoC, exploit, or patch information is provided.

    0000089
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43578 Privilege Escalation in OpenClaw 2026.3.31 via Heartbeat Owner Downgrade Detection https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43578

    Post summary

    The text announces a privilege escalation vulnerability (CVE‑2026‑43578) in OpenClaw 2026.3.31 due to heartbeat owner downgrade detection, with a link to detail but no PoC, patch, or exploitation evidence.

    0000049
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more