CVE-2026-56694 Details
Description
NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forged or stale connect callback values to wire messaging channels into out-of-scope agent groups, exposing unauthorized groups to unapproved channels and enabling unauthorized observation or control of restricted agent group activity.
A privilege escalation vulnerability has been identified in NanoClaw versions prior to 2.1.0. The issue arises in the channel-registration approval process, where the function handling channel approval responses does not properly validate admin privileges for target agent groups. This oversight allows scoped admins to send forged or outdated callback values that can connect messaging channels to agent groups outside their scope. As a result, unauthorized groups may be exposed to unapproved channels, enabling unauthorized monitoring or control over restricted group activities.
Users are advised to update to NanoClaw version 2.1.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nanocoai/nanoclaw/commit/0eef8fafdd7c475ab5fd8d37ea566a81e74cd834 | [email protected] | Source CodeVendor |
| https://github.com/nanocoai/nanoclaw/pull/2566 | [email protected] | Issue TrackingVendor |
| https://www.vulncheck.com/advisories/nanoclaw-privilege-escalation-via-forged-channel-approval-callback | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NanoClaw | < 2.1.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion