CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-32846: openclaw through 2026.3.23 (inclusive); +1 more affected products

CVE-2026-32846. CVSS 3.1 base score 7.5 (HIGH, NVD). EPSS 0.00734 (percentile 0.52872), scored 2026-10-06.

Affected technology

openclaw · through 2026.3.23 (inclusive)
openclaw

OpenClaw · 0 to before 2026.3.28
OpenClaw

Description’s affected range: before 2026.3.28

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Attackers can exploit incomplete validation and the allowBareFilename bypass to reference files outside the intended application sandbox, resulting in disclosure of sensitive information including system files, environment files, and SSH keys. Vendor/CNA’s CVSS 4.0 assessment (base score 8.7/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-22
CCR priority
30.2 /100 (P4)
CVSS 3.1
7.5 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N · NVD
EPSS
0.00734 · percentile 0.52973 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-32846.html