PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-32064 OpenClaw CVE debrief

OpenClaw versions prior to 2026.2.21 contain a vulnerability in the sandbox browser entrypoint, launching x11vnc without authentication for noVNC observer sessions. This allows unauthenticated access to the VNC interface on the host loopback interface. The vulnerability impacts defenders who use the sandbox browser, requiring prompt verification and remediation. Evidence is limited to CVE record and source item details; further verification may be necessary to assess exposure and prioritize remediation.

Vendor
OpenClaw
Product
Unknown
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-21
Original CVE updated
2026-10-08
Advisory published
2026-03-21
Advisory updated
2026-10-08

Who should care

Defenders and administrators responsible for OpenClaw deployments, particularly those using the sandbox browser, should assess exposure and prioritize remediation. They should verify and restrict access to the exposed noVNC port on the host loopback interface. Remediation priority is high for OpenClaw versions prior to 2026.2.21. Evidence is limited to CVE record and source item details; further verification may be necessary to assess exposure and mitigate

Why it matters

CVE-2026-32064 allows unauthenticated access to the VNC interface in OpenClaw versions prior to 2026.2.21, impacting defenders who use the sandbox browser and requiring prompt verification and remediation.

  • Unauthenticated access to the VNC interface may allow observation or interaction with the sandbox browser.
  • Defenders may need to verify and restrict access to the exposed noVNC port on the host loopback interface.
  • Remediation priority is high for OpenClaw versions prior to 2026.2.21.
  • Evidence is limited to CVE record and source item details; further verification may be necessary.

Technical summary

The OpenClaw sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface on the host loopback interface. This vulnerability impacts defenders who use the sandbox browser, requiring prompt verification and remediation. The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to vendor advisories and patch commits. Defenders should prioritize verifying and remediating OpenClaw versions prior to 2026.2.21, focusing on systems and deployments using the sandbox browser.

Defensive priority

Defenders should prioritize verifying and remediating OpenClaw versions prior to 2026.2.21, focusing on systems and deployments using the sandbox browser.

Recommended defensive actions

  • Verify OpenClaw versions in use and identify systems or deployments that may be affected by this vulnerability.
  • Apply patches or updates to OpenClaw to version 2026.2.21 or later.
  • Monitor for and restrict access to the exposed noVNC port on the host loopback interface.
  • Review and update defensive configurations and compensating controls for systems using OpenClaw.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to vendor advisories and patch commits. Evidence is limited, and defenders should verify and restrict access to the exposed noVNC port on the host loopback interface. Further verification may be necessary to assess exposure and prioritize remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-32064 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-32064

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-32064 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-32064

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • OpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC Observer

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/32xxx/CVE-2026-32064.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph

    Supplemental source - vendor-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661

    Supplemental source - patch

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/openclaw-missing-vnc-authentication-in-sandbox-browser-novnc-observer

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.