PT-2026-51531 · Nanoclaw · Nanoclaw

·

CVE-2026-56693

·

Published

2026-06-23

·

Updated

2026-06-23

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NanoClaw versions prior to 2.1.17
Description A privilege escalation issue exists in the create agent delivery-action handler. The handler performs privileged central-database writes without implementing host-side authorization checks. This allows confined agent containers to invoke create agent to create arbitrary agent groups, container configurations, and destinations, enabling them to escalate privileges beyond their intended confinement boundary.
Recommendations Update to version 2.1.17 or later.

Exploit

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56693

Affected Products

Nanoclaw