Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

45735 risultati

VulnerabilitàAlta
CVE-2026-32895 - OpenClaw < 2026.2.26 - Sender Authorization Bypass in Slack System Event Handlers

CVE ID :CVE-2026-32895 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event handlers, allowing unauthorized events to be enqueued. Attackers can bypass Slack DM allowlists and per-channel user allowlists by sending system events from non-allowlisted senders through message_changed, message_deleted, and thread_broadcast events. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32898 - OpenClaw < 2026.2.23 - ACP Permission Auto-Approval Bypass via Untrusted Tool Metadata

CVE ID :CVE-2026-32898 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves tool calls based on untrusted toolCall.kind metadata and permissive name heuristics. Attackers can bypass interactive approval prompts for read-class operations by spoofing tool metadata or using non-core read-like names to reach auto-approve paths. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32064 (CVSS 7.7)

OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-32056 (CVSS 7.5)

OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attackers to bypass command allowlist protections. Remote attackers can inject malicious startup files such as .bash_profile or .zshenv to achieve arbitrary code execution before allowlist-evaluated commands are executed.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-32065 - OpenClaw < 2026.2.25 - Approval Identity Mismatch in system.run Command Execution

CVE ID :CVE-2026-32065 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval identity while trimming argv token whitespace, but runtime execution uses raw argv. An attacker can craft a trailing-space executable token to execute a different binary than what the approver displayed, allowing unexpected command execution under the OpenClaw runtime user when they can influence command argv and reuse an approval context. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32064 - OpenClaw < 2026.2.21 - Missing VNC Authentication in Sandbox Browser noVNC Observer

CVE ID :CVE-2026-32064 Published : March 21, 2026, 1:17 a.m. | 27 minutes ago Description :OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthenticated access to the VNC interface. Remote attackers on the host loopback interface can connect to the exposed noVNC port to observe or interact with the sandbox browser without credentials. Severity: 8.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32057 - OpenClaw < 2026.2.25 - Authentication Bypass via Control UI client.id Parameter

CVE ID :CVE-2026-32057 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that accepts client.id=control-ui without proper device identity verification. An authenticated node role websocket client can exploit this by using the control-ui client identifier to skip pairing requirements and gain unauthorized access to node event execution flows. Severity: 6.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32058 - OpenClaw < 2026.2.26 - Approval Context-Binding Weakness in system.run via host=node

CVE ID :CVE-2026-32058 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of previously approved requests with modified environment variables. Attackers with access to an approval id can exploit this by reusing an approval with changed env input, bypassing execution-integrity controls in approval-enabled workflows. Severity: 2.6 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32056 - OpenClaw < 2026.2.22 - Remote Code Execution via Shell Startup Environment Variable Injection in system.run

CVE ID :CVE-2026-32056 Published : March 21, 2026, 1:17 a.m. | 27 minutes ago Description :OpenClaw versions prior to 2026.2.22 fail to sanitize shell startup environment variables HOME and ZDOTDIR in the system.run function, allowing attackers to bypass command allowlist protections. Remote attackers can inject malicious startup files such as .bash_profile or .zshenv to achieve arbitrary code execution before allowlist-evaluated commands are executed. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026
VulnerabilitàAlta
CVE-2026-32055 (CVSS 7.6)

OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files outside the workspace through in-workspace symlinks pointing to non-existent out-of-root targets. The vulnerability exists because the boundary check improperly resolves aliases, permitting the first write operation to escape the workspace boundary and create files in arbitrary locations.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-32051 (CVSS 8.8)

OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to invoke owner-only tool surfaces including gateway and cron through agent runs in scoped-token deployments. Attackers with write-scope access can perform control-plane actions beyond their intended authorization level by exploiting inconsistent owner-only gating during agent execution.

NVD (NIST)21 mar 2026
VulnerabilitàAlta
CVE-2026-32052 - OpenClaw < 2026.2.24 - Hidden Command Execution via Shell-Wrapper Positional argv Carriers

CVE ID :CVE-2026-32052 Published : March 21, 2026, 1:17 a.m. | 2 hours, 27 minutes ago Description :OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidden commands by injecting positional argv carriers after inline shell payloads. Attackers can craft misleading approval text while executing arbitrary commands through trailing positional arguments that bypass display context validation. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE21 mar 2026

Pagina 3242 di 3812

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.