|
431
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of the narrower operator.pairing scope, allowing unpr…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-42426
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
5.3 |
MEDIUM
Local
|
-
|
-
|
OpenClaw before 2026.4.8 contains a remote code execution vulnerability caused by missing environment variable denylist entries for HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUSTC_WRAPPER, and MAKEFLAGS. …
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-42427
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
7.1 |
HIGH
Network
|
-
|
-
|
OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without detection, compromising the…
New
|
CWE-353
Missing Support for Integrity Check
|
CVE-2026-42428
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
7.1 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that widens identity-bearing operator.read requests into runtime operator.wr…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-42429
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allows attackers to bypass strict SSRF checks. Attackers can exploit request-time na…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42430
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
8.1 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. Attackers can exploit this path to circumvent the …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-42431
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
7.8 |
HIGH
Local
|
-
|
-
|
OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without operator.admin scope requirement. Attackers can…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-42432
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
- |
|
-
|
-
|
A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request.
New
|
CWE-694
Use of Multiple Resources with Duplicate Identifier
|
CVE-2026-5794
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to
trigger improper handling of XML input, which may result in unintended
exposure of sensitive information. The flaw stems from in…
New
|
CWE-611
XXE
|
CVE-2026-6807
|
2026-04-29 05:10 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
6.5 |
MEDIUM
Network
|
apache
|
storm
|
Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm
Versions Affected: up to 2.8.7
Description: When TLS transport is enabled in Apache …
New
|
CWE-287
Improper Authentication
|
CVE-2026-41081
|
2026-04-29 04:46 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|