Vulnerability Description
OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted completion content to leave a run in a more privileged context than intended.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | >= 2026.3.31, < 2026.4.10 |
Related Weaknesses (CWE)
References
- https://github.com/openclaw/openclaw/commit/19a2e9ddb5a8a494abcba812bb11f5107502Patch
- https://github.com/openclaw/openclaw/security/advisories/GHSA-g375-h3v6-4873MitigationVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-privilege-escalation-via-missed-asThird Party Advisory
FAQ
What is CVE-2026-43578?
CVE-2026-43578 is a vulnerability with a CVSS score of 9.1 (CRITICAL). OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can ...
How severe is CVE-2026-43578?
CVE-2026-43578 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-43578?
Check the references section above for vendor advisories and patch information. Affected products include: Openclaw Openclaw.