OpenClaw versions prior to 2026
Description
OpenClaw versions prior to 2026
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Search and filter 21637 vulnerabilities with AI analyst insights
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions 2026
OpenClaw versions 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions before 2026.2.24 contain a sandbox network isolation bypass vulnerability allowing trusted operators to access other container netwo...
OpenClaw versions before 2026.2.24 contain a sandbox network isolation bypass vulnerability allowing trusted operators to access other container networks.
Update Docker Multiple Products to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was identified in z-9527 admin 1
A vulnerability was identified in z-9527 admin 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions 2026
OpenClaw versions 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
JWT Tokens used by tasks were exposed in logs
JWT Tokens used by tasks were exposed in logs
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Apache OFBiz contains a vulnerability involving the use of hard-coded cryptographic keys, which could allow unauthorized decryption or manipulation of...
Apache OFBiz contains a vulnerability involving the use of hard-coded cryptographic keys, which could allow unauthorized decryption or manipulation of sensitive data.
---METADATA---
VENDOR: Apache
PRODUCT: OFBiz
AFFECTED_VERSIONS: before 24.09.06
---END_METADATA---
Description Summary:
Apache OFBiz contains a vulnerability involving the use of hard-coded cryptographic keys, which could allow unauthorized decryption or manipulation of sensitive data.
Executive Summary:
A critical hard-coded cryptographic key vulnerability in Apache OFBiz poses a severe risk of data compromise and unauthorized system access.
Vulnerability Details
CVE-ID: CVE-2026-31986
Affected Software: Apache OFBiz
Affected Versions: before 24.09.06
Vulnerability: This vulnerability involves the presence of hard-coded cryptographic keys within the application, which may allow an unauthenticated attacker to bypass security controls or decrypt sensitive information.
Business Impact
With a CVSS score of 9.1, this vulnerability represents a critical risk to organizational data integrity and confidentiality. Successful exploitation could lead to full unauthorized access to encrypted data streams or the ability to forge session tokens, potentially resulting in complete system compromise and significant reputational damage.
Remediation Plan
Immediate Action: Upgrade Apache OFBiz to version 24.09.06 or higher immediately to eliminate the hard-coded keys.
Proactive Monitoring: Monitor server logs for unusual decryption errors or patterns of unauthorized access requests originating from unexpected sources.
Compensating Controls: Implement strict network segmentation and restrict access to the OFBiz management interface to trusted IP addresses only until patching is completed.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of May 19, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given the critical nature of this cryptographic flaw, organizations must prioritize patching Apache OFBiz environments. Immediate remediation is required to prevent potential data breaches that could arise from the exposure of hard-coded credentials.
Update Apache OFBiz to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verificati...
When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it
---METADATA---
VENDOR: Nozomi Networks
PRODUCT: Remote Collector
AFFECTED_VERSIONS: 0 up to (excluding) 26.2.0
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Nozomi Remote Collector fails to verify TLS certificates when configured via n2os-tui, exposing communication to potential interception.
Executive Summary:
A vulnerability in the Nozomi Remote Collector configuration process disables TLS certificate verification, creating a significant risk of man-in-the-middle attacks.
Vulnerability Details
CVE-ID: CVE-2026-31985
Affected Software: Nozomi Networks Remote Collector
Affected Versions: 0 up to (excluding) 26.2.0
Vulnerability: This is an authentication-related security flaw (CWE-671) where the n2os-tui tool generates configurations that disable TLS certificate verification by default. The vulnerability is exploitable by an unauthenticated attacker positioned to intercept network traffic between the collector and the upstream Guardian or CMC.
Business Impact
Successful exploitation allows an attacker to perform man-in-the-middle attacks, potentially intercepting or altering data transmitted between the Remote Collector and the management console. With a CVSS score of 8.1, the high potential for data integrity compromise necessitates immediate attention to ensure secure communication channels within the monitoring infrastructure.
Remediation Plan
Immediate Action: Upgrade the Nozomi Remote Collector software to version 26.2.0 or later to ensure TLS certificate verification is enforced.
Proactive Monitoring: Review network communication logs for unexpected connections or certificate mismatch errors originating from the Remote Collector.
Compensating Controls: Isolate the management network segment to minimize the number of entities capable of intercepting traffic between the collector and the management console.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 9, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
The reliance on unverified TLS certificates undermines the fundamental security of the monitoring architecture. Administrators should prioritize the deployment of version 26.2.0 to restore cryptographic validation and mitigate the risk of traffic interception.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
SAMtools is a program for reading, manipulating and writing bioinformatics file formats
SAMtools is a program for reading, manipulating and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HTSlib is a library for reading and writing bioinformatics file formats
HTSlib is a library for reading and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HTSlib is a library for reading and writing bioinformatics file formats
HTSlib is a library for reading and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HTSlib is a library for reading and writing bioinformatics file formats
HTSlib is a library for reading and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HTSlib is a library for reading and writing bioinformatics file formats
HTSlib is a library for reading and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HTSlib is a library for reading and writing bioinformatics file formats
HTSlib is a library for reading and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HTSlib is a library for reading and writing bioinformatics file formats
HTSlib is a library for reading and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HTSlib is a library for reading and writing bioinformatics file formats
HTSlib is a library for reading and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HTSlib is a library for reading and writing bioinformatics file formats
HTSlib is a library for reading and writing bioinformatics file formats
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Himmelblau allows unauthenticated remote attackers to bypass tenant-scoped authentication when no tenant domain is configured, enabling unauthorized a...
Himmelblau allows unauthenticated remote attackers to bypass tenant-scoped authentication when no tenant domain is configured, enabling unauthorized access via dynamic provider registration.
---METADATA---
VENDOR: Himmelblau
PRODUCT: Himmelblau
AFFECTED_VERSIONS: 3.0.0 to before 3.1.0
---END_METADATA---
Description Summary:
Himmelblau allows unauthenticated remote attackers to bypass tenant-scoped authentication when no tenant domain is configured, enabling unauthorized access via dynamic provider registration.
Executive Summary:
A critical authentication vulnerability in Himmelblau allows unauthenticated attackers to bypass domain restrictions and gain access to Microsoft Azure Entra ID and Intune environments.
Vulnerability Details
CVE-ID: CVE-2026-31957
Affected Software: Himmelblau Interoperability Suite
Affected Versions: 3.0.0 to before 3.1.0
Vulnerability: When deployed without a configured tenant domain in himmelblau.conf, the suite fails to enforce tenant-scoped authentication. This allows an unauthenticated attacker to use arbitrary Entra ID domains by dynamically registering providers at runtime, bypassing intended security boundaries in remote environments.
Business Impact
This flaw permits unauthorized access to sensitive enterprise identity and device management platforms. Given the CVSS score of 10, the risk includes total compromise of Azure Entra ID and Intune configurations, leading to unauthorized data access and potential lateral movement across the corporate cloud infrastructure.
Remediation Plan
Immediate Action: Update the Himmelblau suite to version 3.1.0 immediately and ensure a specific tenant domain is configured in the himmelblau.conf file.
Proactive Monitoring: Review authentication logs for login attempts from unexpected or unknown Entra ID domains and monitor for dynamic provider registration events.
Compensating Controls: Use IP allowlisting to restrict access to the Himmelblau service and implement multi-factor authentication (MFA) across all identity providers.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Mar 11, 2026, there is no public information indicating active exploitation of this vulnerability. The "bootstrap" nature of this behavior increases the likelihood of misconfiguration in production environments.
Analyst Recommendation
Organizations relying on Himmelblau for Azure interoperability must treat this as a top-priority remediation. The ability to bypass tenant scoping effectively nullifies identity boundaries, necessitating an immediate update to version 3.1.0 to restore secure authentication.
Update Microsoft Azure Entra to the latest version. Monitor for exploitation attempts and review access logs.
Xibo is an open source digital signage platform with a web content management system and Windows display player software
Xibo is an open source digital signage platform with a web content management system and Windows display player software
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenOlat fails to verify JWT signatures in its OpenID Connect implicit flow implementation, allowing attackers to bypass authentication by providing f...
OpenOlat fails to verify JWT signatures in its OpenID Connect implicit flow implementation, allowing attackers to bypass authentication by providing forged, unverified tokens.
---METADATA---
VENDOR: OpenOlat
PRODUCT: OpenOlat (e-learning platform)
AFFECTED_VERSIONS: 10.5.4 to before 20.2.5
---END_METADATA---
Description Summary:
OpenOlat fails to verify JWT signatures in its OpenID Connect implicit flow implementation, allowing attackers to bypass authentication by providing forged, unverified tokens.
Executive Summary:
OpenOlat’s failure to cryptographically verify JWT signatures allows unauthenticated attackers to forge identity tokens and gain unauthorized access to the e-learning platform.
Vulnerability Details
CVE-ID: CVE-2026-31946
Affected Software: OpenOlat OpenOlat (e-learning platform)
Affected Versions: 10.5.4 to before 20.2.5
Vulnerability: The OpenID Connect implementation in OpenOlat incorrectly parses JWTs by discarding the signature segment without verification. Because the getAccessToken() method only validates non-cryptographic claims like audience and issuer, an unauthenticated attacker can craft a malicious JWT that the system accepts as valid.
Business Impact
This flaw effectively nullifies the security of the OpenID Connect authentication mechanism, leading to potential widespread account takeovers and unauthorized access to sensitive educational data. The CVSS score of 9.8 underscores the critical nature of this authentication bypass, which threatens the privacy of students and staff and the overall integrity of the platform.
Remediation Plan
Immediate Action: Upgrade OpenOlat installations to version 20.2.5 or higher, which introduces mandatory cryptographic signature verification against the Identity Provider's JWKS endpoint.
Proactive Monitoring: Audit authentication logs for unusual login patterns or JWTs lacking standard headers, and monitor for unauthorized access to administrative or privileged user accounts.
Compensating Controls: If an immediate update is not possible, consider temporarily disabling OIDC implicit flow or enforcing secondary authentication factors where applicable.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Mar 30, 2026, there is no public information indicating active exploitation of this vulnerability. However, the technical details provided in the disclosure make the creation of a functional exploit trivial for a motivated attacker.
Analyst Recommendation
The absence of signature verification is a fundamental security failure in any OIDC implementation. Administrators must treat this as a top-priority security event and apply the 20.2.5 patch immediately to ensure that only authenticated, verified users can access the system.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features
---METADATA---
VENDOR: LibreChat
PRODUCT: LibreChat
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
LibreChat, an open-source ChatGPT clone, contains a high-severity vulnerability that could impact the security of the AI interface and user data.
Executive Summary:
LibreChat is affected by a high-severity security vulnerability that could allow attackers to compromise the application environment or gain unauthorized access to user sessions.
Vulnerability Details
CVE-ID: CVE-2026-31945
Affected Software: LibreChat
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability exists in the LibreChat application, a platform for interfacing with various AI models. With a CVSS score of 7.7, the flaw likely involves improper input validation or a session management issue that could be exploited by an attacker to intercept data or perform actions on behalf of users.
Business Impact
Exploitation of this vulnerability could lead to the exposure of sensitive AI prompts, API keys, and private conversations. In a corporate environment, this represents a significant data leak risk. The High severity rating (7.7) reflects the potential for attackers to disrupt the service or compromise the privacy of all users on the platform.
Remediation Plan
Immediate Action: Administrators of LibreChat instances should pull the latest Docker images or update the source code to the most recent patched version immediately.
Proactive Monitoring: Review application logs for suspicious API calls or unauthorized attempts to access the administrative dashboard.
Compensating Controls: Implement a reverse proxy with strong authentication (e.g., OAuth or SAML) to protect the LibreChat interface from direct public exposure.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 29, 2026, there is no public information indicating active exploitation. However, open-source AI tools are currently high-interest targets for researchers and malicious actors alike.
Analyst Recommendation
Given the increasing use of AI clones in business workflows, this vulnerability should be treated with high priority. Administrators must ensure their LibreChat deployments are updated to the latest version to protect user data and maintain the integrity of the AI environment.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features
---METADATA---
VENDOR: LibreChat
PRODUCT: LibreChat
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
LibreChat, an open-source ChatGPT clone, contains a vulnerability that could allow for unauthorized access to application features or user data.
Executive Summary:
LibreChat is affected by a high-severity vulnerability that could lead to the compromise of user conversations and sensitive application configurations.
Vulnerability Details
CVE-ID: CVE-2026-31944
Affected Software: LibreChat
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability exists in the LibreChat application framework, which provides additional features over standard AI interfaces. The flaw likely involves improper access control or input validation, potentially allowing an attacker to interact with the system in an unauthorized manner.
Business Impact
The impact of this vulnerability includes potential data breaches involving private AI conversations and the exposure of API keys or other secrets stored within the LibreChat environment. With a CVSS score of 7.6, the risk is high, as it directly threatens the privacy of users and the security of integrated AI services.
Remediation Plan
Immediate Action: Update the LibreChat deployment to the latest version available on the official repository to patch the security flaw.
Proactive Monitoring: Audit user activity logs for unusual login patterns or unauthorized access to administrative features.
Compensating Controls: Deploy the application behind a reverse proxy with strong authentication and utilize a WAF to inspect incoming traffic for malicious payloads.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 14, 2026, there is no public information indicating active exploitation of this vulnerability. However, open-source AI tools are frequent targets for attackers seeking to harvest credentials or sensitive data.
Analyst Recommendation
Administrators of LibreChat instances should prioritize the application of security updates to protect user privacy and organizational assets. Immediate remediation is necessary to ensure that the AI chat environment remains secure against unauthorized access and data exfiltration.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features
---METADATA---
VENDOR: LibreChat
PRODUCT: LibreChat
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
A high-severity vulnerability has been identified in LibreChat, a ChatGPT clone, which may lead to unauthorized access or system compromise.
Executive Summary:
LibreChat is affected by a high-severity security flaw that could compromise the confidentiality and integrity of the AI chat platform.
Vulnerability Details
CVE-ID: CVE-2026-31943
Affected Software: LibreChat
Affected Versions: See vendor advisory for affected versions
Vulnerability: While the specific technical vector is not detailed in the summary, the high CVSS score of 8.5 suggests a significant flaw, likely involving improper access control or input validation within the LibreChat application.
Business Impact
A successful exploit could allow attackers to access private chat histories, manipulate AI responses, or gain unauthorized access to the application's underlying infrastructure. Given the CVSS score of 8.5, this vulnerability poses a substantial risk to user privacy and organizational data security, potentially leading to regulatory non-compliance.
Remediation Plan
Immediate Action: Apply the latest security updates provided by the LibreChat maintainers immediately to close the identified security gap.
Proactive Monitoring: Review application logs for unusual API calls or unauthorized attempts to access user sessions and administrative settings.
Compensating Controls: Implement strong authentication mechanisms, such as Multi-Factor Authentication (MFA), and use a Web Application Firewall to monitor incoming traffic for malicious patterns.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 28, 2026, there is no public information indicating active exploitation of this vulnerability. Users should remain vigilant as ChatGPT clones are increasingly targeted by threat actors seeking to harvest credentials or session tokens.
Analyst Recommendation
The high severity of this vulnerability requires immediate attention. Organizations deploying LibreChat should verify their current version and update to the latest patched release to ensure the continued security of their AI communications and data.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Chamilo LMS is a learning management system
Chamilo LMS is a learning management system
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Chamilo LMS is a learning management system
Chamilo LMS is a learning management system
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Chamilo LMS is a learning management system
Chamilo LMS is a learning management system
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
jsPDF versions prior to 4.2.1 are vulnerable to HTML and script injection via the output function's options argument, leading to Cross-Site Scripting...
jsPDF versions prior to 4.2.1 are vulnerable to HTML and script injection via the output function's options argument, leading to Cross-Site Scripting (XSS).
---METADATA---
VENDOR: jsPDF Project
PRODUCT: jsPDF Library
AFFECTED_VERSIONS: Prior to version 4.2.1
---END_METADATA---
Description Summary:
jsPDF versions prior to 4.2.1 are vulnerable to HTML and script injection via the output function's options argument, leading to Cross-Site Scripting (XSS).
Executive Summary:
The jsPDF JavaScript library contains a critical vulnerability that allows attackers to inject malicious scripts into the browser context of victims who open generated PDFs.
Vulnerability Details
CVE-ID: CVE-2026-31938
Affected Software: jsPDF Library
Affected Versions: Prior to version 4.2.1
Vulnerability: The output function fails to sanitize the options argument, allowing an unauthenticated attacker to provide malicious HTML or scripts. When a victim opens a PDF generated with these options, the script executes within their browser context.
Business Impact
This vulnerability facilitates Cross-Site Scripting (XSS), which can lead to the theft of session cookies, sensitive data, or the modification of the user's browser environment. Given the CVSS score of 9.6, the risk is critical as it allows for remote code execution in the client's browser, potentially compromising internal web applications that utilize the library.
Remediation Plan
Immediate Action: Upgrade the jsPDF library to version 4.2.1 or higher to resolve the sanitization failure in the output function.
Proactive Monitoring: Review application code to identify where user-controlled input is passed to the jsPDF library and ensure all inputs are strictly validated.
Compensating Controls: As a temporary workaround, implement robust server-side and client-side sanitization of any user input before it is passed to the output method of the jsPDF library.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Mar 18, 2026, there is no public information indicating active exploitation of this vulnerability. However, the technical ease of injecting scripts into JavaScript libraries makes this a high-priority target for attackers.
Analyst Recommendation
Organizations using jsPDF for dynamic document generation must update to version 4.2.1 immediately. Failure to do so leaves end-users vulnerable to script injection attacks that can bypass browser security boundaries and compromise sensitive session data.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
---METADATA---
VENDOR: Suricata
PRODUCT: Suricata Engine
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
A vulnerability identified in the Suricata network engine could be exploited to disrupt security monitoring or bypass detection mechanisms.
Executive Summary:
Suricata IDS/IPS sensors are affected by a high-severity vulnerability that poses a direct threat to network security and threat detection capabilities.
Vulnerability Details
CVE-ID: CVE-2026-31937
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability resides in the Suricata engine, impacting its network IDS and IPS functions. An unauthenticated attacker could potentially exploit this flaw through specially crafted network traffic, leading to a denial of service or detection evasion.
Business Impact
With a CVSS score of 7.5, this vulnerability represents a high risk to organizational security. A failure in the Suricata engine can leave the network vulnerable to various attacks, leading to potential data breaches, system compromise, and significant reputational damage if an intrusion goes undetected.
Remediation Plan
Immediate Action: Update all affected Suricata instances to the latest secure version immediately to mitigate the risk of exploitation.
Proactive Monitoring: Monitor for unexpected service restarts or unusual traffic patterns that might indicate an attempt to exploit the IDS engine.
Compensating Controls: Maintain up-to-date endpoint security and centralized logging to provide alternative methods of detection for malicious activity.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. However, the high severity underscores the need for prompt patching.
Analyst Recommendation
Immediate action is required to patch the Suricata engine. Security administrators should prioritize this update to ensure that the network's primary intrusion detection and prevention system remains effective and resilient.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
---METADATA---
VENDOR: Suricata
PRODUCT: Suricata Engine
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
A high-severity flaw in the Suricata engine could compromise the reliability of network intrusion detection and prevention.
Executive Summary:
The Suricata network IDS/IPS engine is vulnerable to an exploit that could lead to engine failure or the evasion of security controls.
Vulnerability Details
CVE-ID: CVE-2026-31935
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability affects the Suricata engine's ability to process network traffic correctly. An unauthenticated remote attacker could exploit this flaw to cause a denial of service or to bypass the security signatures intended to protect the network.
Business Impact
The compromise of a network security engine like Suricata can result in a complete loss of visibility into malicious network activity. Given the CVSS score of 7.5, the risk of a successful attack is high, potentially leading to long-term undetected access by adversaries and significant remediation costs.
Remediation Plan
Immediate Action: Apply the recommended security patches for Suricata as soon as they are made available by the vendor or distribution.
Proactive Monitoring: Regularly audit the Suricata configuration and performance metrics to ensure the engine is operating at full capacity and without errors.
Compensating Controls: Deploy additional network-level security measures, such as access control lists (ACLs) on routers, to provide a baseline level of protection.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. The complexity of modern network traffic makes engine-level vulnerabilities a constant threat.
Analyst Recommendation
Apply the primary remediation patch immediately. Ensuring the continued operation and integrity of the IDS/IPS infrastructure is paramount to maintaining an effective security posture against modern threats.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
---METADATA---
VENDOR: Suricata
PRODUCT: Suricata Engine
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
A vulnerability in Suricata's network engine could allow an attacker to bypass intrusion detection signatures or crash the inspection service.
Executive Summary:
Suricata, a critical network security engine, contains a high-severity vulnerability that could be exploited to disable or evade network monitoring.
Vulnerability Details
CVE-ID: CVE-2026-31934
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This flaw exists in the Suricata network IDS/IPS engine. It allows an unauthenticated attacker to potentially bypass security rules or cause a denial-of-service condition by sending malformed or specifically sequenced network traffic to the affected sensor.
Business Impact
With a CVSS score of 7.5, this vulnerability represents a significant threat to network security operations. An effective exploit could disable the organization's "first line of defense," leading to increased risk of undetected breaches, intellectual property theft, and non-compliance with security standards.
Remediation Plan
Immediate Action: Upgrade the Suricata engine to the most recent version provided by the vendor to close the identified security gap.
Proactive Monitoring: Enable detailed logging for the Suricata engine to capture evidence of potential exploitation attempts or malformed packet processing errors.
Compensating Controls: Utilize a multi-vendor security strategy where possible to ensure that a single point of failure in one IDS engine does not leave the network entirely unprotected.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. However, the high severity and potential for IDS evasion make this a critical issue for security teams.
Analyst Recommendation
Immediate remediation via patching is strongly advised. Organizations should treat this as a high-priority update to ensure that their network monitoring capabilities are not compromised by external actors.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
---METADATA---
VENDOR: Suricata
PRODUCT: Suricata Engine
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
The Suricata engine is vulnerable to a flaw that could result in a denial of service or the bypass of network security policies.
Executive Summary:
Suricata network security sensors are affected by a high-severity vulnerability that could compromise the integrity of network traffic inspection.
Vulnerability Details
CVE-ID: CVE-2026-31933
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability resides within the Suricata engine, which functions as a network IDS and IPS. An unauthenticated attacker may be able to trigger this flaw by sending specific network packets, potentially leading to a crash of the Suricata process or a failure to inspect certain traffic.
Business Impact
A CVSS score of 7.5 indicates a high severity level, as this flaw directly undermines the primary defensive mechanism for the network. A successful exploit could lead to unauthorized network access going unnoticed, resulting in data exfiltration, malware propagation, or significant operational disruptions.
Remediation Plan
Immediate Action: Update all Suricata installations to the latest patched version available from the vendor.
Proactive Monitoring: Implement external monitoring for the Suricata service status to detect and respond to any engine crashes in real-time.
Compensating Controls: Ensure that secondary security controls, such as NetFlow analysis, are active to provide visibility if the primary IDS fails.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. Security researchers frequently target IDS engines, increasing the likelihood of an exploit being developed.
Analyst Recommendation
Apply the necessary patches without delay. Maintaining the health of network security infrastructure is a critical component of a robust defense-in-depth strategy, and this update is essential for risk mitigation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
---METADATA---
VENDOR: Suricata
PRODUCT: Suricata Engine
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
A security flaw in the Suricata IDS/IPS engine could permit attackers to interfere with network traffic analysis and security enforcement.
Executive Summary:
A vulnerability in the Suricata network engine poses a high risk to network visibility and the effectiveness of intrusion prevention measures.
Vulnerability Details
CVE-ID: CVE-2026-31932
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability involves a defect in the Suricata engine's packet handling or protocol analysis modules. An unauthenticated remote attacker could leverage this flaw to disrupt the monitoring capabilities of the IDS or cause the service to fail.
Business Impact
The failure of an IDS/IPS engine can lead to a "blind spot" in the corporate network, allowing malicious actors to operate without detection. With a CVSS score of 7.5, the potential for system downtime and the resulting loss of security oversight represents a significant risk to organizational assets and data security.
Remediation Plan
Immediate Action: Deploy the official security updates for Suricata immediately to address this engine-level vulnerability.
Proactive Monitoring: Review Suricata alert logs for anomalies and ensure that the engine is not dropping packets or entering an error state.
Compensating Controls: Use network segmentation to limit the blast radius of any potential intrusion that might bypass the affected IDS sensors.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. The critical nature of IDS software makes this a high-value target for attackers seeking to evade detection.
Analyst Recommendation
It is imperative to apply the recommended updates immediately. Security teams must treat any vulnerability in their monitoring infrastructure with the highest urgency to ensure that defensive capabilities remain intact.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Suricata is a network IDS, IPS and NSM engine
Suricata is a network IDS, IPS and NSM engine
---METADATA---
VENDOR: Suricata
PRODUCT: Suricata Engine
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
A high-severity vulnerability has been identified in the Suricata network IDS/IPS engine that may impact traffic inspection.
Executive Summary:
The Suricata network security engine is affected by a vulnerability that could allow attackers to bypass security monitoring or cause a denial of service.
Vulnerability Details
CVE-ID: CVE-2026-31931
Affected Software: Suricata Engine
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability affects the core processing engine of Suricata, a network intrusion detection and prevention system. An unauthenticated attacker could potentially send specially crafted network traffic to exploit this flaw, leading to engine instability or detection evasion.
Business Impact
As a critical component of network defense, a vulnerability in Suricata directly impacts the organization's ability to detect and block threats. The CVSS score of 7.5 reflects a high risk where the security appliance itself becomes a point of failure, potentially leading to undetected lateral movement by attackers or network downtime.
Remediation Plan
Immediate Action: Apply the latest security patches provided by the Suricata development team or your specific distribution maintainer.
Proactive Monitoring: Monitor the health and performance of Suricata sensors for unexpected crashes or high CPU utilization that may indicate exploitation.
Compensating Controls: Implement redundant security layers, such as host-based firewalls and endpoint detection, to mitigate the impact if the network IDS is bypassed.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 4, 2026, there is no public information indicating active exploitation of this vulnerability. Given Suricata's role in security, any flaw in its engine is a high-priority concern for network administrators.
Analyst Recommendation
Immediate patching of all Suricata instances is required to maintain the security posture of the network. Administrators should verify that the engine is correctly processing traffic after the update to ensure continued protection against network-based threats.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed dur...
The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation
---METADATA---
VENDOR: Daktronics
PRODUCT: VFC-DMP-5000
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
Daktronics VFC-DMP-5000 devices utilize default administrative credentials with weak authentication controls, posing a significant risk of unauthorized access.
Executive Summary:
Daktronics VFC-DMP-5000 units are susceptible to unauthorized administrative access due to the use of insecure, non-mandatory default credentials.
Vulnerability Details
CVE-ID: CVE-2026-31928
Affected Software: Daktronics VFC-DMP-5000
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This is a credential management vulnerability where the device ships with a default administrative account. The lack of enforced password changes during initial setup allows for potential unauthenticated access by remote attackers.
Business Impact
The risk of unauthorized administrative access is critical, as it provides an attacker with full control over the device. With a CVSS score of 8.1, this vulnerability could lead to total system compromise, unauthorized data modification, or the use of the device as a pivot point for further lateral movement within the network.
Remediation Plan
Immediate Action: Manually change the default administrative credentials immediately and ensure strong, unique passwords are enforced for all management interfaces.
Proactive Monitoring: Monitor network traffic for unauthorized login attempts or unusual management console access patterns.
Compensating Controls: Place the device management interface behind a secure VPN or restrict access to specific, trusted management IP addresses via firewall rules.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of June 27, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Default credential vulnerabilities are a common target for automated exploitation tools. It is imperative that all organizations deploying these devices perform an immediate credential audit and enforce password rotation policies to mitigate the risk of unauthorized access.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fox-lms allows Blind SQL Injecti...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fox-lms allows Blind SQL Injection
---METADATA---
VENDOR: Ays Pro
PRODUCT: Fox LMS (WordPress Plugin)
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
The Ays Pro Fox LMS plugin for WordPress is vulnerable to Blind SQL Injection, allowing attackers to exfiltrate data from the database through inference.
Executive Summary:
The Ays Pro Fox LMS plugin contains a high-severity Blind SQL Injection vulnerability that enables attackers to silently extract sensitive information from the WordPress database.
Vulnerability Details
CVE-ID: CVE-2026-31922
Affected Software: Ays Pro Fox LMS (fox-lms)
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability is a Blind SQL Injection flaw caused by improper neutralization of user-supplied input in SQL commands. An attacker can use time-based or boolean-based techniques to infer the contents of the database, even without direct error messages.
Business Impact
With a CVSS score of 8.5, this vulnerability poses a significant threat to the confidentiality of student and course data. Attackers could steal user hashes, personal details, and administrative credentials, leading to a full site takeover and long-term data exfiltration.
Remediation Plan
Immediate Action: Apply the latest security update for the Ays Pro Fox LMS plugin immediately to close the SQL Injection vector.
Proactive Monitoring: Monitor for unusually slow database response times, which can be a symptom of time-based Blind SQL Injection attempts.
Compensating Controls: Utilize database-level security controls and a WAF to detect and drop suspicious requests containing SQL keywords or logical operators.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 15, 2026, there is no public information indicating active exploitation. Blind SQL Injection is harder to detect than standard SQLi but is equally dangerous for data integrity.
Analyst Recommendation
Given the high severity, immediate patching is mandatory. Organizations using Fox LMS must update the plugin to the latest version to prevent unauthorized data access and protect the privacy of their learning management system.
Apply vendor patches immediately. Review database access controls and enable query logging.
Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrec...
Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection
---METADATA---
VENDOR: weDevs
PRODUCT: WP ERP (WordPress Plugin)
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
The weDevs WP ERP plugin for WordPress is vulnerable to SQL Injection, which could allow attackers to extract or modify database information.
Executive Summary:
A high-severity SQL Injection vulnerability in the weDevs WP ERP plugin allows attackers to compromise the underlying WordPress database, leading to full data exposure.
Vulnerability Details
CVE-ID: CVE-2026-31917
Affected Software: weDevs WP ERP
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The plugin fails to properly neutralize special elements in SQL commands, resulting in a classic SQL Injection flaw. This allows an attacker to inject malicious SQL queries through vulnerable parameters, potentially bypassing authentication or extracting sensitive data.
Business Impact
The CVSS score of 8.5 indicates a severe risk. A successful exploit could lead to the complete compromise of the WordPress database, including user credentials, financial records, and proprietary business data managed within the ERP system, resulting in catastrophic data loss and reputational damage.
Remediation Plan
Immediate Action: Update the weDevs WP ERP plugin to the latest patched version immediately to remediate the SQL Injection vulnerability.
Proactive Monitoring: Enable database query logging and review for suspicious SQL patterns, such as "UNION SELECT" or unexpected administrative account creations.
Compensating Controls: Deploy a Web Application Firewall (WAF) with SQL Injection protection rules to block malicious payloads targeting the ERP plugin.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 15, 2026, there is no public information indicating active exploitation. However, SQL Injection remains one of the most frequently exploited vulnerability classes in WordPress environments.
Analyst Recommendation
The high CVSS score and the nature of the vulnerability demand immediate action. Administrators must patch the WP ERP plugin without delay to prevent a total database compromise and ensure the security of their business operations.
Apply vendor patches immediately. Review database access controls and enable query logging.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz
---METADATA---
VENDOR: Apache
PRODUCT: OFBiz
AFFECTED_VERSIONS: 0 up to (excluding) 24.09.06
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A Server-Side Request Forgery (SSRF) vulnerability exists in Apache OFBiz that allows unauthenticated attackers to send unauthorized requests from the server.
Executive Summary:
An unauthenticated SSRF vulnerability in Apache OFBiz allows remote attackers to perform unauthorized requests, potentially leading to internal network reconnaissance.
Vulnerability Details
CVE-ID: CVE-2026-31910
Affected Software: Apache OFBiz
Affected Versions: 0 up to (excluding) 24.09.06
Vulnerability: This is a Server-Side Request Forgery (CWE-918) vulnerability occurring in Apache OFBiz. The flaw allows an unauthenticated, remote attacker to influence the server's request-making capabilities, as indicated by the CVSS vector AV:N/AC:L/PR:N.
Business Impact
Successful exploitation allows an attacker to bypass perimeter security to access internal network resources, query sensitive APIs, or perform port scanning of internal infrastructure. While the CVSS score is 7.5, the potential for internal network compromise makes this a significant risk for organizations hosting OFBiz in sensitive environments.
Remediation Plan
Immediate Action: Upgrade to Apache OFBiz version 24.09.06 or later immediately.
Proactive Monitoring: Monitor network traffic originating from the OFBiz server for unexpected connections to internal services or non-standard external endpoints.
Compensating Controls: If patching is delayed, implement strict egress filtering on the application server to prevent connections to unauthorized internal or external destinations.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of May 20, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to its potential to bypass network segmentation and interact with internal services that are not designed to face the public internet.
Analyst Recommendation
The vulnerability poses a moderate-to-high risk to organizational infrastructure due to the potential for internal network exposure. Administrators should prioritize updating to version 24.09.06 to resolve the underlying SSRF flaw and prevent potential unauthorized internal reconnaissance.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz
---METADATA---
VENDOR: Apache
PRODUCT: OFBiz
AFFECTED_VERSIONS: 0 up to (excluding) 24.09.06
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An information disclosure vulnerability in Apache OFBiz allows unauthenticated attackers to access sensitive data due to inadequate access controls.
Executive Summary:
An unauthenticated information exposure vulnerability in Apache OFBiz could allow an attacker to gain access to sensitive system or business data.
Vulnerability Details
CVE-ID: CVE-2026-31909
Affected Software: Apache OFBiz
Affected Versions: 0 up to (excluding) 24.09.06
Vulnerability: This is an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability. Based on the CVSS vector AV:N/AC:L/PR:N, the vulnerability is reachable by an unauthenticated attacker via the network.
Business Impact
Successful exploitation could result in the unauthorized disclosure of sensitive business information, potentially including customer data, system configuration details, or credentials. A CVSS score of 7.5 reflects the high impact on confidentiality, which could lead to regulatory compliance failures and reputational harm.
Remediation Plan
Immediate Action: Upgrade to Apache OFBiz version 24.09.06 or later to apply the necessary security fixes.
Proactive Monitoring: Review application access logs for unusual patterns or bulk data retrieval requests that may indicate an attempt to exploit this information disclosure.
Compensating Controls: Ensure the OFBiz instance is not exposed to the public internet unless strictly necessary, and enforce strict access controls at the network level.
Exploitation Status
Public Exploit Available: Unknown.
Analyst Notes: As of May 20, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The lack of authentication requirements makes this a highly accessible target for attackers seeking sensitive information.
Analyst Recommendation
Given the potential for unauthorized data access, immediate remediation is required. Organizations should apply the vendor-provided update to version 24.09.06 as soon as possible to ensure the confidentiality of their data.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
---METADATA---
VENDOR: WebSocket API Provider
PRODUCT: WebSocket Application Programming Interface
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
The WebSocket Application Programming Interface lacks necessary restrictions on the frequency of authentication requests, facilitating automated credential attacks.
Executive Summary:
The WebSocket API is vulnerable to brute-force authentication attacks due to a lack of request rate limiting, posing a high risk of unauthorized system access.
Vulnerability Details
CVE-ID: CVE-2026-31904
Affected Software: WebSocket API Provider WebSocket Application Programming Interface
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The application's WebSocket interface does not enforce a maximum threshold for authentication attempts. This allows an unauthenticated attacker to programmatically attempt thousands of password combinations without being blocked or delayed by the system.
Business Impact
Failure to restrict authentication attempts can result in widespread account compromise and the exposure of proprietary data handled via the WebSocket API. This leads to loss of data integrity and potential regulatory non-compliance regarding access controls. The CVSS score of 7.5 justifies the High severity rating, as the flaw directly impacts the confidentiality and integrity of the system.
Remediation Plan
Immediate Action: Update the affected software to the most recent version that includes fixes for authentication rate limiting.
Proactive Monitoring: Implement real-time alerting for high-frequency authentication failures and monitor for source IPs that deviate from normal traffic patterns.
Compensating Controls: Utilize an external identity provider or an API security layer to enforce multi-factor authentication (MFA) and request-per-second limits.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 22, 2026, there is no public information indicating active exploitation of this vulnerability. Despite the lack of a public exploit, the technical barrier to entry for exploiting this flaw is extremely low.
Analyst Recommendation
This vulnerability represents a critical weakness in the authentication architecture of the WebSocket API. It is imperative that administrators apply the recommended security updates immediately. Relying on password complexity alone is insufficient when an attacker can perform unlimited attempts; therefore, patching is the only effective long-term mitigation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: OpenClaw
PRODUCT: OpenClaw
AFFECTED_VERSIONS: Before 2026.2.24
---END_METADATA---
Description Summary:
OpenClaw versions before 2026.2.24 contain a sandbox network isolation bypass vulnerability allowing trusted operators to access other container networks.
Executive Summary:
OpenClaw is vulnerable to a critical network isolation bypass that allows authenticated operators to violate container boundaries and access restricted services.
Vulnerability Details
CVE-ID: CVE-2026-32038
Affected Software: OpenClaw
Affected Versions: Before 2026.2.24
Vulnerability: This flaw allows a trusted operator to join another container's network namespace by manipulating the
docker.networkparameter. By usingcontainer:<id>values, an attacker can bypass network hardening controls and reach services that should be isolated within other container namespaces.Business Impact
While this exploit requires "trusted operator" (authenticated) status, it represents a significant breakdown of the security model in containerized environments. An insider threat or a compromised operator account could use this to pivot across the infrastructure, accessing sensitive services or data in supposedly isolated containers. The CVSS score of 9.8 reflects the high potential for lateral movement.
Remediation Plan
Immediate Action: Update OpenClaw to version 2026.2.24 or later to enforce proper network namespace isolation and prevent the bypass.
Proactive Monitoring: Audit container configuration changes and monitor for unusual inter-container network traffic that deviates from established security policies.
Compensating Controls: Implement strict IAM policies to limit who can modify container network parameters and use network-level micro-segmentation to provide defense-in-depth.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Mar 19, 2026, there is no public information indicating active exploitation. This vulnerability is particularly relevant for multi-tenant environments where network isolation is a primary security requirement.
Analyst Recommendation
Container escape and isolation bypasses are high-impact events. Even though authentication is required, the potential for lateral movement within a cloud or data center environment is severe. Apply the 2026.2.24 update immediately to maintain the integrity of your container security boundaries.