Junglewise Threat Intelligence

CVE-2026-8621: openclaw Crabbox authentication bypass via identity header spoofing

CVE-2026-8621 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Openclaw Crabbox, github.com/openclaw/crabbox (Go). Vendors: Openclaw, Go.

Executive brief

Crabbox, a tool used for managing cloud-based development environments and leases, contains a security flaw in how it handles shared authentication tokens. An attacker with a valid shared token can impersonate other users or organizations by including fake identity information in their web requests. This allows the attacker to view, modify, or manage resources belonging to other accounts, potentially leading to unauthorized data access or service disruption.

Technical details

An authentication bypass vulnerability exists in Crabbox's coordinator component due to improper validation of identity headers when using shared-token authentication. The `authenticateRequest()` function incorrectly trusts caller-supplied `X-Crabbox-Owner` and `X-Crabbox-Org` headers for requests authenticated with a valid `CRABBOX_SHARED_TOKEN`. An attacker with low privileges (possession of a shared token) can inject these headers to spoof their identity as a victim user or organization. This allows the attacker to bypass authorization checks and perform owner-scoped operations, such as reading lease details or managing resources belonging to others. The vulnerability is fixed in version 0.12.0 by ignoring these headers for shared-token callers and instead using server-controlled identity sources.

Affected products

  • openclaw Crabbox < 0.12.0

Timeline

  • 2026-05-10: other: Fix submitted via pull request
  • 2026-05-12: patched: Version 0.12.0 released
  • 2026-05-14: disclosed: CVE published and advisory released

References

Related threats