PT-2026-26741 · Novnc+2 · Novnc+2
Rafael M
·
Published
2026-03-03
·
Updated
2026-03-22
·
CVE-2026-32064
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.21
Description
The OpenClaw sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, granting unauthenticated access to the VNC interface. Attackers on the host loopback interface can connect to the exposed noVNC port and observe or interact with the sandbox browser without credentials. The issue affects versions prior to 2026.2.21.
Recommendations
Update OpenClaw to version 2026.2.21 or later.
Fix
Missing Authentication
Missing Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw
Novnc
X11Vnc