---
id: CVE-2026-32064
title: >-
  OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches
  x11vnc without authentication for noVNC observer sessions, allowing
  unauthenticated access to the VNC interface
summary: >-
  OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches
  x11vnc without authentication for noVNC observer sessions, allowing
  unauthenticated access to the VNC interface. Remote attackers on the host
  loopback interface can…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-306
vendor: openclaw
product: openclaw
affected:
  - openclaw < 2026.2.21
patched:
  - openclaw 2026.2.21
published: '2026-03-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:12.833'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-32064'
references:
  - url: >-
      https://github.com/openclaw/openclaw/commit/621d8e1312482f122f18c43c72c67211b141da01
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/commit/8c1518f0f3e0533593cd2dec3a46c9b746753661
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/openclaw/openclaw/security/advisories/GHSA-25gx-x37c-7pph
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/openclaw-missing-vnc-authentication-in-sandbox-browser-novnc-observer
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-23T17:27:59.360571Z'
epss: 0.00586
epssPercentile: 0.46305
ingestedAt: '2026-10-08T16:52:14.675Z'
---

## Overview

OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.

## Affected

- `openclaw < 2026.2.21`

## Remediation

Upgrade past the affected range:

- `openclaw 2026.2.21`
