PatchSiren cyber security CVE debrief
CVE-2026-32064 OpenClaw CVE debrief
OpenClaw versions prior to 2026.2.21 contain a vulnerability in the sandbox browser entrypoint, launching x11vnc without authentication for noVNC observer sessions. This allows unauthenticated access to the VNC interface on the host loopback interface. The vulnerability impacts defenders who use the sandbox browser, requiring prompt verification and remediation. Evidence is limited to CVE record and source item details; further verification may be necessary to assess exposure and prioritize remediation.
- Vendor
- OpenClaw
- Product
- Unknown
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-21
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-03-21
- Advisory updated
- 2026-10-08
Who should care
Defenders and administrators responsible for OpenClaw deployments, particularly those using the sandbox browser, should assess exposure and prioritize remediation. They should verify and restrict access to the exposed noVNC port on the host loopback interface. Remediation priority is high for OpenClaw versions prior to 2026.2.21. Evidence is limited to CVE record and source item details; further verification may be necessary to assess exposure and mitigate
Why it matters
CVE-2026-32064 allows unauthenticated access to the VNC interface in OpenClaw versions prior to 2026.2.21, impacting defenders who use the sandbox browser and requiring prompt verification and remediation.
- Unauthenticated access to the VNC interface may allow observation or interaction with the sandbox browser.
- Defenders may need to verify and restrict access to the exposed noVNC port on the host loopback interface.
- Remediation priority is high for OpenClaw versions prior to 2026.2.21.
- Evidence is limited to CVE record and source item details; further verification may be necessary.
Technical summary
The OpenClaw sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface on the host loopback interface. This vulnerability impacts defenders who use the sandbox browser, requiring prompt verification and remediation. The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to vendor advisories and patch commits. Defenders should prioritize verifying and remediating OpenClaw versions prior to 2026.2.21, focusing on systems and deployments using the sandbox browser.
Defensive priority
Defenders should prioritize verifying and remediating OpenClaw versions prior to 2026.2.21, focusing on systems and deployments using the sandbox browser.
Recommended defensive actions
- Verify OpenClaw versions in use and identify systems or deployments that may be affected by this vulnerability.
- Apply patches or updates to OpenClaw to version 2026.2.21 or later.
- Monitor for and restrict access to the exposed noVNC port on the host loopback interface.
- Review and update defensive configurations and compensating controls for systems using OpenClaw.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to vendor advisories and patch commits. Evidence is limited, and defenders should verify and restrict access to the exposed noVNC port on the host loopback interface. Further verification may be necessary to assess exposure and prioritize remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-32064 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-32064
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-32064 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32064
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
OpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC Observer
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/32xxx/CVE-2026-32064.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph
Supplemental source - vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/openclaw-missing-vnc-authentication-in-sandbox-browser-novnc-observer
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.