CVE-2026-32064 impacts OpenClaw versions prior to 2026.2.21, stemming from the sandbox browser's noVNC observer sessions launching x11vnc without proper authentication. This critical vulnerability (CVSS 9.1) allows remote attackers on the host loopback interface to connect to the exposed noVNC port, gaining unauthenticated access to observe or interact with the sandbox browser. The attack complexity is low, with a high potential for confidentiality and integrity impact. There is currently no evidence of active exploitation, nor are public exploit codes available. Community discussion and media coverage for this vulnerability remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.21CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.21CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.