๐Ÿ” CVE Alert

CVE-2026-8629

HIGH 8.1

Crabbox < v0.12.0 Privilege Escalation via Agent Ticket Endpoints

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests to ticket endpoints. Attackers can exploit insufficient access control checks on the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints to obtain bridge-agent tickets and impersonate trusted lease-side bridges despite having only visibility permissions.

CWE CWE-639
Vendor openclaw
Product crabbox
Published May 14, 2026
Last Updated May 14, 2026
Stay Ahead of the Next One

Get instant alerts for openclaw crabbox

Be the first to know when new high vulnerabilities affecting openclaw crabbox are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

openclaw / crabbox
0 < 0.12.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/openclaw/crabbox/releases/tag/v0.12.0 github.com: https://github.com/openclaw/crabbox/pull/71 github.com: https://github.com/openclaw/crabbox/commit/95cb30dc7dbaa1fef690a42ef6ac1cb6e307a191 vulncheck.com: https://www.vulncheck.com/advisories/crabbox-privilege-escalation-via-agent-ticket-endpoints

Credits

Chia Min Jun Lennon