CVE-2026-32064 Details
Description
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.
A vulnerability exists in OpenClaw versions prior to 2026.2.21, where the sandbox browser entrypoint launches x11vnc for noVNC observer sessions without authentication. This flaw allows remote attackers on the host loopback interface to access the VNC interface and interact with the sandbox browser without credentials. The issue arises because the noVNC port is published to the host loopback only, creating a default local exposure that can be exploited if the port is exposed more broadly.
Users can update to OpenClaw version 2026.2.21 or later, which requires VNC password authentication for noVNC observer sessions. After updating, it's recommended to verify that noVNC ports are only published to the loopback interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openclaw openclaw | < 2026.2.21 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 24, 2026 | Initial Analysis | [email protected] |
| Mar 21, 2026 | New CVE Received | [email protected] |