Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.5

OpenClaw Sandbox Browser Allows Unauthenticated Access to VNC Interface

CVE-2026-32064
Summary

OpenClaw versions prior to 2026.2.21 have a security flaw that lets hackers access the browser without a password. This can happen when a hacker is on the same network as the computer running OpenClaw. To fix this, update to OpenClaw version 2026.2.21 or later.

Original title
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote atta...
Original description
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.
nvd CVSS3.1 7.7
nvd CVSS4.0 8.5
Vulnerability type
CWE-306 Missing Authentication for Critical Function
Published: 21 Mar 2026 · Updated: 21 Mar 2026 · First seen: 21 Mar 2026