CVE-2026-43566: Openclaw

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. Attackers can exploit this by sending untrusted webhook wake events to preserve owner-like execution context when the run should have been downgraded.

Affected products

  • Openclaw Openclaw: from 2026.4.7, before 2026.4.14 (fixed in 2026.4.14)

Published 2026-05-05. Last modified 2026-06-17.