CVE-2026-8629 Details
Description
Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.
A privilege escalation vulnerability has been identified in Crabbox versions prior to 0.12.0. This vulnerability allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets. Exploitation involves sending POST requests to specific ticket endpoints, where insufficient access control checks allow the unauthorized acquisition of bridge-agent tickets. This enables impersonation of trusted lease-side bridges, despite the attacker only having visibility permissions.
Users are advised to update to Crabbox version 0.12.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 14, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/openclaw/crabbox/pull/71 | CISA-ADP | Issue TrackingVendor |
| https://github.com/openclaw/crabbox/commit/95cb30dc7dbaa1fef690a42ef6ac1cb6e307a191 | [email protected] | Source CodeVendor |
| https://github.com/openclaw/crabbox/pull/71 | [email protected] | Issue TrackingVendor |
| https://github.com/openclaw/crabbox/releases/tag/v0.12.0 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/crabbox-privilege-escalation-via-agent-ticket-endpoints | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Crabbox | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | New CVE Received | [email protected] |
| May 14, 2026 | CVE Modified | CISA-ADP |
Volerion