TopVuln

High-risk vulnerability digests

CVE-2026-43566

  • CRITICAL

Details

CVSS v3
9.1
CVSS v4
9.1
NVD published
2026-05-05 12:16:20
EPSS
0.1% probability · 29.2th percentile — 2026-05-07
Affected versions
OpenClaw 2026.4.7 to before 2026.4.14
Summary
This is a critical privilege escalation vulnerability in OpenClaw. The heartbeat owner downgrade logic incorrectly skips validation of webhook wake events carrying untrusted content. Attackers can exploit this flaw to retain privileged owner-like execution context that should have been revoked after downgrade.
Remediation
Update OpenClaw to version 2026.4.14 or later immediately. Restrict unauthenticated access to webhook endpoints as a temporary mitigation before applying the patch.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.