OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.
References
Configurations
History
No history.
Information
Published : 2026-03-21 01:17
Updated : 2026-03-24 21:10
NVD link : CVE-2026-32064
Mitre link : CVE-2026-32064
CVE.ORG link : CVE-2026-32064
JSON object : View
Products Affected
openclaw
- openclaw
CWE
CWE-306
Missing Authentication for Critical Function
