← back
CVE-2026-56694mediumCWE-863

NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
In short

NanoClaw before version 2.1.0 allows administrators with limited permissions to trick the system into connecting messaging channels to groups they shouldn't have access to, potentially exposing restricted activities to unauthorized monitoring or control.

Technical detail

The vulnerability exists in the channel-registration approval flow where handleChannelApprovalResponse does not properly verify that an admin has appropriate privileges over target agent groups. Scoped admins can submit forged or stale callback values to establish messaging channels within out-of-scope agent groups, bypassing intended access controls and enabling unauthorized observation or control of restricted group operations.

Summary generated and translated by AI from the official description.
NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forged or stale connect callback values to wire messaging channels into out-of-scope agent groups, exposing unauthorized groups to unapproved channels and enabling unauthorized observation or control of restricted agent group activity.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
nanocoai · nanoclaw