Vulnerabilidades em OpenClaw

584 resultados
Análise Vexday

Com 495 CVEs catalogadas e nenhuma confirmada em exploração ativa no momento, o perfil do OpenClaw apresenta taxa de exploração confirmada abaixo da média geral do catálogo KEV. O dado que merece atenção imediata é o volume de 323 vulnerabilidades surgidas nos últimos 90 dias, indicando um ritmo elevado de descobertas recentes que ainda pode não ter atraído atenção de agentes maliciosos, mas amplia consideravelmente a superfície de ataque. O tipo de falha mais comum é CWE-863 (autorização incorreta), o que sugere fragilidades estruturais no controle de acesso — categoria com alto potencial de impacto caso explorada. A CVE mais perigosa identificada atualmente, CVE-2026-25253, apresenta EPSS de 0,0802, e embora não haja PoC pública disponível, equipes de segurança devem monitorar sua evolução dado o contexto de crescimento acelerado no volume de vulnerabilidades do vendor.

CVE-2026-32042HIGHOpenClaw < 2026.2.25 - Privilege Escalation via Unpaired Device Identity in Shared Gateway AuthenticationEPSS 0.4%CVE-2026-28460MEDIUMOpenClaw < 2026.2.22 - Allowlist Bypass via Shell Line-Continuation Command Substitution in system.runEPSS 0.4%CVE-2026-28478HIGHOpenClaw < 2026.2.13 - Denial of Service via Unbounded Webhook Request Body BufferingEPSS 0.4%CVE-2026-35640MEDIUMOpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request ParsingEPSS 0.4%CVE-2026-32036HIGHOpenClaw < 2026.2.26- Authentication Bypass via Encoded Dot-Segment Traversal in /api/channelsEPSS 0.4%CVE-2026-29607HIGHOpenClaw < 2026.2.22 - Authorization Bypass via allow-always Wrapper PersistenceEPSS 0.4%CVE-2026-29609HIGHOpenClaw < 2026.2.14 - Denial of Service via Unbounded URL-backed Media FetchEPSS 0.4%CVE-2026-32062HIGHOpenClaw 2026.2.21-2 < 2026.2.22 - Unauthenticated WebSocket Resource Exhaustion via Media StreamEPSS 0.4%CVE-2026-28462HIGHOpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output PathsEPSS 0.4%CVE-2026-26329HIGHOpenClaw has a path traversal in browser upload allows local file readEPSS 0.4%CVE-2026-35652MEDIUMOpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback DispatchEPSS 0.4%CVE-2026-28466CRITICALOpenClaw < 2026.2.14 - Remote Code Execution via Node Invoke Approval BypassEPSS 0.4%CVE-2026-53810HIGHOpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension MetadataEPSS 0.4%CVE-2026-53806HIGHOpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec RevalidationEPSS 0.4%CVE-2026-27566HIGHOpenClaw < 2026.2.22 - Allowlist Bypass via Wrapper Binary Unwrapping in system.runEPSS 0.4%CVE-2026-32982HIGHOpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error LogsEPSS 0.4%CVE-2026-43566CRITICALOpenClaw 2026.4.7 < 2026.4.14 - Privilege Escalation via Untrusted Webhook Wake EventsEPSS 0.4%CVE-2026-42437HIGHOpenClaw 2026.4.9 < 2026.4.10 - Denial of Service via Oversized WebSocket Frames in Voice-call Realtime PathEPSS 0.4%CVE-2026-41370HIGHOpenClaw < 2026.3.31 - Path Traversal via Inbound Channel Attachment Path in ACP DispatchEPSS 0.4%CVE-2026-41346MEDIUMOpenClaw 2026.2.26 < 2026.3.31 - Denial of Service via Improper Pending Pairing Request Cap EnforcementEPSS 0.4%