Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 3 April 2026
RSS74 vulnerabilities published on 3 April 2026
Severity:
Azure Databricks: Unauthenticated Network Access from Application
CVE-2026-33107
An attacker can use Azure Databricks to access and control systems on your network without permission. This could allow them to steal data, disrupt operations, or install malware. To protect your comp...
10.0
Microsoft Azure Kubernetes Service Unauthorized Privilege Escalation
CVE-2026-33105
An attacker can access and control Azure Kubernetes Service resources without permission, potentially leading to unauthorized changes or data breaches. This affects organizations that use Azure Kubern...
10.0
Azure AI Foundry Privilege Elevation via Unauthorized Access
CVE-2026-32213
An unauthorized user can gain elevated privileges on a network by exploiting a weakness in Azure AI Foundry's authorization process. This means they could potentially access or tamper with sensitive d...
10.0
Azure Custom Locations RP Allows Privilege Elevation Over Network
CVE-2026-26135
An attacker with permission to manage Azure Custom Locations can use this issue to gain control over network resources. This could allow them to access sensitive data or disrupt services. Users should...
9.6
OpenClaw: Attackers Can Escape From the Safe Sandbox
GHSA-9p3r-hh9g-5cmg
A security issue in OpenClaw allows attackers to escape from a safe area of the system and access sensitive information. This affects users who are running version 2026.3.28 or earlier of the OpenClaw...
9.4
OpenClaw: Files Accessed Outside of Safe Area
GHSA-cwf8-44x6-32c2
OpenClaw software allows attackers to access files outside a safe area, potentially leading to unauthorized data access or modification. This issue affects versions of OpenClaw installed through npm b...
9.4
Azure MCP Server Exposes Critical Data to Unauthorized Access
CVE-2026-32211
A mistake in Azure MCP Server's authentication process makes it possible for unauthorized users to access sensitive information over the network. This means that an attacker could potentially see conf...
9.1
OpenClaw: Workspace Environment Variables Can Override Plugin Trust
GHSA-qcj9-wwgw-6gm8
If an attacker controls the workspace environment variables, they can potentially bypass security settings in OpenClaw. This is a high-risk issue, but it requires an attacker to have control over the ...
8.9
OpenClaw: Untrusted Node Access Can Lead to Gateway Takeover
GHSA-gjm7-hw8f-73rq
An attacker can take control of a gateway computer if they have access to a paired node that is not properly secured. This is a serious issue because it allows an attacker to execute arbitrary code on...
8.7
OpenClaw: Unrestricted File Sync and Symlink Traversal Risks Malicious File Access
GHSA-cwf8-44x6-32c2
OpenClaw versions up to 2026.3.28 have a security flaw that allows a hacker to access and manipulate files on the system. This is due to unrestricted file syncing and the ability to create symlinks, w...
8.7
OpenClaw: Unbound Bootstrapping Allows Unauthorized Access
GHSA-gg9v-mgcp-v6m7
The OpenClaw software has a security weakness that could allow an attacker to gain more access than they should during the initial setup process. This is a serious issue, as it could potentially lead ...
8.6
OpenClaw: Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode
GHSA-g374-mggx-p6xc
## Summary
Incomplete scope-clearing fix allows operator.admin escalation via trusted-proxy auth mode
## Current Maintainer Triage
- Normalized severity: high
- Assessment: v2026.3.28 still misses tr...
8.6
Azure SRE Agent: Unauthorized Access to Network Data
CVE-2026-32173
An attacker can exploit a weakness in the Azure SRE Agent to access sensitive information sent over a network if they don't have permission to do so. This could lead to the exposure of confidential da...
8.6
OpenClaw Media Download Exposes Authorization Headers in Redirects
GHSA-68v4-hmwv-f43h
A security issue in OpenClaw version 2026.3.28 and earlier allows attackers to steal sensitive information when a user downloads media from a different website. This is a medium-risk vulnerability tha...
8.3
Electron apps: Video frame transfer via contextBridge can give attackers control
GHSA-jfqg-hf23-qpw2
CVE-2026-34780
Electron apps that share video data between browser and Node.js environments are at risk of being compromised by an attacker who can inject malicious code. To fix, avoid sharing video frames directly ...
8.3
OpenClaw: LLM Agent Can Disable Exec Approval without User Consent
GHSA-v3qc-wrwx-j3pw
A security issue was found in OpenClaw, a library used by developers. A malicious agent could bypass the need for user approval to execute certain actions, potentially leading to unauthorized changes....
8.2
Electron: Using child windows with offscreen rendering can crash apps
GHSA-532v-xpq5-8h95
CVE-2026-34774
If you're using Electron to create apps with child windows and also render content offscreen, be aware that this setup can cause your app to crash or become unstable. To fix this, make sure to close c...
8.1
OpenClaw Discord Audio Processing Exposes User Data Before Authorization
GHSA-hhff-fj5f-qg48
The OpenClaw software processes Discord audio before checking if the user is authorized, potentially exposing sensitive information. This could happen to anyone using an outdated version of OpenClaw. ...
7.8
OpenClaw: Unpaired Device Can Access Host Privileges
GHSA-xj9w-5r6q-x6v4
An unsecured device can access sensitive host commands, potentially allowing an attacker to take control of the host system. This vulnerability affects devices paired with OpenClaw version 2026.3.28 o...
7.7
Electron: Malicious Code Can Bypass Security Settings
GHSA-9wfr-w7mm-pc7f
CVE-2026-34769
If you use Electron to build desktop apps, be careful when using user input to configure your app's settings. An attacker could trick your app into disabling security features by injecting malicious c...
7.7
OpenClaw Node Browser Proxy Allows Bypass of Access Controls
GHSA-h5hg-h7rr-gpf3
A security issue in OpenClaw's node browser proxy allows an attacker to bypass access controls and gain unauthorized access to profiles. This means that sensitive data may be exposed if you're using a...
7.6
Electron: Apps may crash when handling fullscreen or pointer-lock requests
GHSA-8337-3p73-46f4
CVE-2026-34771
Some Electron apps that ask users for permission to use their computer in fullscreen, pointer-lock, or keyboard-lock mode may crash or become unstable if a user navigates away or closes the window whi...
7.5
Sudo: Privilege Escalation from Setuid/setgid/setgroups Failure
CVE-2026-35535
The Sudo software has a security issue where certain errors during user privilege changes can lead to unauthorized access. This affects users who rely on Sudo for secure access to system features. To ...
7.4
OpenClaw: Untrusted Model Can Hijack Compiler Binaries
GHSA-g8xp-qx39-9jq9
A security flaw in OpenClaw allows an untrusted model to replace critical compiler binaries, which could potentially lead to malicious code being executed. This issue affects versions of OpenClaw up t...
7.3
OpenClaw: Workspace .env File Can Override Trust Settings
GHSA-qcj9-wwgw-6gm8
A high-risk issue exists in OpenClaw versions up to 2026.3.28, where a workspace's .env file can override the trust settings for bundled plugins. This could allow an attacker to gain unauthorized acce...
7.3