2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43572MEDIUM6.3OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO in...
CVE-2026-43571HIGH8.8OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to reso...
CVE-2026-43570MEDIUM6.5OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository p...
CVE-2026-43569HIGH8.8OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto...
CVE-2026-43568HIGH7.1OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators...
CVE-2026-43567HIGH7.1OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that byp...
CVE-2026-43566CRITICAL9.8OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade...
CVE-2026-43535HIGH8.1OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allow...
CVE-2026-43534CRITICAL9.8OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued a...
CVE-2026-43533HIGH8.9OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to ref...
CVE-2026-43532HIGH7.7OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc...
CVE-2026-43531HIGH8.8OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env file...
CVE-2026-43530HIGH8.8OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybo...
CVE-2026-43529LOW2.5OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed func...
CVE-2026-43528HIGH7.1OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive...
CVE-2026-43527HIGH7.7OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows privat...
CVE-2026-43526CRITICAL9.3OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that al...
CVE-2026-42439HIGH8.5OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action ...
CVE-2026-42438HIGH7.7OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media atta...
CVE-2026-42437HIGH8.2OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSock...
CVE-2026-42436HIGH7.7OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab rou...
CVE-2026-42435HIGH8.8OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing...
CVE-2026-42434HIGH8.8OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override...
CVE-2026-42433HIGH7.1OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to a...
CVE-2026-6322HIGH7.5fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now