Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 24 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nanoco
Nanoco nanoclaw |
|
| Vendors & Products |
Nanoco
Nanoco nanoclaw |
Tue, 23 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation. | |
| Title | NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Handler | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T17:47:24.204Z
Reserved: 2026-06-21T12:37:58.435Z
Link: CVE-2026-56402
Updated: 2026-06-23T17:47:12.738Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T16:00:06Z