9.1
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/SC:N
Description
OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted completion content to leave a run in a more privileged context than intended.
AI Analysis
Privilege escalation vulnerability in OpenClaw via missed async exec completion events in heartbeat owner downgrade detection
Basic Information
ID
CVE-2026-43578
Source
VulnCheck
Published
May 6, 2026 at 19:49
Affected Product
Vendor
OpenClaw
Product
OpenClaw
Version
2026.3.31
Affected Versions
OpenClaw OpenClaw 2026.3.31
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
OpenClaw
Product
OpenClaw
Version
2026.3.31