{"id":"CVE-2026-56693","title":"NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks","summary":"NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invok…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-602"],"vendor":"nanocoai","product":"nanoclaw","affected":["nanoclaw < 2.1.17"],"published":"2026-06-23","updated":"2026-09-17","sourceUpdated":"2026-09-17T18:16:52.233","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56693","references":[{"url":"https://github.com/nanocoai/nanoclaw/commit/ac37ecbfd6b9d14fdfa1598a6412a8ffdbeaef45","label":"disclosure@vulncheck.com"},{"url":"https://github.com/nanocoai/nanoclaw/pull/2720","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/nanoclaw-privilege-escalation-via-unauthorized-create-agent-system-action","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-06-23T15:47:48.499266Z"},"epss":0.00165,"epssPercentile":0.05094,"ingestedAt":"2026-09-17T18:25:15.972Z","slug":"CVE-2026-56693","body":"## Overview\n\nNanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent groups, container configurations, and destinations, escalating beyond their intended confinement boundary.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}