HIGH
OpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC Observer
Published Mar 21, 2026
8.5
HIGHCVSS 4.0
EPSS 0.59%
Description
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.
Affected products
-
Affected
- ≥ 0, < 2026.2.21
Unaffected
- 2026.2.21
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.2.21
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.2.21 |
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-13964 Advisory
- https://github.com/advisories/GHSA-25gx-x37c-7pph Advisory
- https://github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01 patch
- https://github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661 patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph vendor-advisoryMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-32064
- https://www.vulncheck.com/advisories/openclaw-missing-vnc-authentication-in-sandbox-browser-novnc-observer third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-13964 | Advisory | |
| https://github.com/advisories/GHSA-25gx-x37c-7pph | Advisory | |
| https://github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01 | patch | |
| https://github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661 | patch | |
| https://github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph | vendor-advisoryMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-32064 | ||
| https://www.vulncheck.com/advisories/openclaw-missing-vnc-authentication-in-sandbox-browser-novnc-observer | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 21, 2026
Updated Jun 23, 2026
Reserved Mar 10, 2026
Link CVE-2026-32064
CISA Vulnrichment
Updated Mar 23, 2026
Red Hat
No data
GitHub
Link GHSA-25GX-X37C-7PPH