2026 CVE Vulnerabilities

67,342 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32038CRITICAL9OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to joi...
CVE-2026-32037MEDIUM6.5OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts al...
CVE-2026-32036HIGH8.2OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers ...
CVE-2026-32035HIGH7.1OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in age...
CVE-2026-32034HIGH8.1OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecure...
CVE-2026-32033MEDIUM6.5OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass works...
CVE-2026-32032HIGH7.8OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback th...
CVE-2026-32031MEDIUM6.5OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authenticati...
CVE-2026-32030HIGH8.2OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accep...
CVE-2026-32029MEDIUM6.3OpenClaw versions prior to 2026.2.21 improperly parse the left-most X-Forwarded-For header value when requests originate...
CVE-2026-32028MEDIUM6.3OpenClaw versions prior to 2026.2.25 fail to enforce dmPolicy and allowFrom authorization checks on Discord direct-messa...
CVE-2026-32027HIGH7.1OpenClaw versions prior to 2026.2.26 contain an authorization bypass vulnerability where DM pairing-store identities are...
CVE-2026-32026HIGH8.6OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that al...
CVE-2026-32025HIGH7.5OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that al...
CVE-2026-32024HIGH7.5OpenClaw versions prior to 2026.2.22 contain a symlink traversal vulnerability in avatar handling that allows attackers ...
CVE-2026-32023HIGH7.1OpenClaw versions prior to 2026.2.24 contain an approval gating bypass vulnerability in system.run allowlist mode where ...
CVE-2026-32022MEDIUM6.5OpenClaw versions prior to 2026.2.21 contain a stdin-only policy bypass vulnerability in the grep tool within tools.exec...
CVE-2026-32021MEDIUM6.5OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the Feishu allowFrom allowlist imp...
CVE-2026-32020MEDIUM5.5OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symb...
CVE-2026-32019MEDIUM5.3OpenClaw versions prior to 2026.2.22 contain incomplete IPv4 special-use range validation in the isPrivateIpv4() functio...
CVE-2026-32018MEDIUM4.8OpenClaw versions prior to 2026.2.19 contain a race condition vulnerability in concurrent updateRegistry and removeRegis...
CVE-2026-32017HIGH7.1OpenClaw versions prior to 2026.2.19 contain an allowlist bypass vulnerability in the exec safeBins policy that allows a...
CVE-2026-32016HIGH7.8OpenClaw versions prior to 2026.2.22 on macOS contain a path validation bypass vulnerability in the exec-approval allowl...
CVE-2026-32015HIGH7.8OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a path hijacking vulnerability in tools.exec.safeBins that allows...
CVE-2026-32014HIGH8.6OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now