A vulnerability labeled as critical has been found in OpenClaw up to 2026.4.9. Impacted is an unknown function. Executing a manipulation can lead to inclusion of functionality from untrusted control sphere.
This vulnerability appears as CVE-2026-43571. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in OpenClaw up to 2026.4.9. This issue affects some unknown processing. Performing a manipulation results in missing authorization.
This vulnerability is reported as CVE-2026-43573. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.4.11. This vulnerability affects unknown code of the component URL Handler. Such manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-43526. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in OpenClaw up to 2026.4.9. It has been rated as critical. This affects an unknown part. This manipulation causes incomplete blacklist.
This vulnerability is registered as CVE-2026-43532. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in OpenClaw up to 2026.4.9. It has been declared as problematic. Affected by this issue is the function validateScriptFileForShellBleed. The manipulation results in time-of-check time-of-use.
This vulnerability is cataloged as CVE-2026-43529. The attack must be initiated from a local position. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in OpenClaw up to 2026.4.9. It has been classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to relative path traversal.
This vulnerability is listed as CVE-2026-43533. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in OpenClaw up to 2026.4.8 and classified as critical. Affected is an unknown function. Executing a manipulation can lead to inclusion of functionality from untrusted control sphere.
This vulnerability is tracked as CVE-2026-43569. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability has been found in OpenClaw up to 2026.4.13 and classified as critical. This impacts an unknown function. Performing a manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2026-43527. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in OpenClaw up to 2026.4.13. This affects an unknown function. Such manipulation leads to incomplete blacklist.
This vulnerability is referenced as CVE-2026-43566. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in OpenClaw up to 2026.4.9. The impacted element is the function screen_record. This manipulation of the argument outPath causes missing authorization.
The identification of this vulnerability is CVE-2026-43567. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in OpenClaw up to 2026.4.11. The affected element is an unknown function. The manipulation results in permissive list of allowed inputs.
This vulnerability was named CVE-2026-43574. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in OpenClaw up to 2026.4.9. Impacted is an unknown function of the component Attachments Handler. The manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2026-42438. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in OpenClaw up to 2026.4.9. This issue affects some unknown processing of the file /tabs/action. Executing a manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2026-42439. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in OpenClaw up to 2026.4.13. This vulnerability affects unknown code. Performing a manipulation results in incorrect privilege assignment.
This vulnerability is known as CVE-2026-43535. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in OpenClaw up to 2026.4.9. This affects an unknown part. Such manipulation leads to insufficient verification of data authenticity.
This vulnerability is traded as CVE-2026-43534. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in OpenClaw up to 2026.4.13. Affected by this issue is some unknown functionality. This manipulation causes missing authorization.
This vulnerability appears as CVE-2026-42436. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.4.9. Affected by this vulnerability is an unknown functionality of the file /dreaming. The manipulation results in missing authorization.
This vulnerability is reported as CVE-2026-43568. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in OpenClaw up to 2026.4.4. It has been rated as critical. Affected is an unknown function. The manipulation leads to symlink following.
This vulnerability is documented as CVE-2026-43570. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in OpenClaw up to 2026.4.8. It has been declared as problematic. This impacts an unknown function of the component Environment Variable Handler. Executing a manipulation can lead to external control of system or configuration setting.
This vulnerability is registered as CVE-2026-43531. The attack needs to be launched locally. No exploit is available.
It is recommended to upgrade the affected component.