CVE-2026-56402 Details
Description
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.
A privilege escalation vulnerability has been identified in NanoClaw versions prior to 2.1.17. The issue arises in the handleApprovalsResponse function, which does not properly verify the authorization of responders' roles. This flaw allows attackers with a valid questionId to approve or reject privileged actions, such as package installations, by sending approval response payloads without adequate role validation.
Users are advised to update to NanoClaw version 2.1.17 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nanocoai/nanoclaw/pull/2478 | CISA-ADP | Issue TrackingVendor |
| https://github.com/nanocoai/nanoclaw/commit/6227bd1a5b016fb1eb76411bb6681b4c924a51a0 | [email protected] | Source CodeVendor |
| https://github.com/nanocoai/nanoclaw/pull/2478 | [email protected] | Issue TrackingVendor |
| https://www.vulncheck.com/advisories/nanoclaw-privilege-escalation-via-unverified-approval-response-handler | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NanoClaw | < 2.1.17 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | [email protected] |
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion