9.1
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Description
OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. Attackers can exploit this by sending untrusted webhook wake events to preserve owner-like execution context when the run should have been downgraded.
AI Analysis
Privilege escalation vulnerability via untrusted webhook wake events
Basic Information
ID
CVE-2026-43566
Source
VulnCheck
Published
May 5, 2026 at 11:25
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Version
2026.4.7
Affected Versions
OpenClaw OpenClaw 2026.4.7
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
OpenClaw
Product
OpenClaw
Version
2026.4.7 before 2026.4.14