Junglewise Threat Intelligence

CVE-2026-8629: Openclaw Crabbox privilege escalation in agent ticket endpoints

CVE-2026-8629 · Severity: high · CVSS 8.1 · Published 2026-05-14

Technologies: Openclaw Crabbox. Vendors: Openclaw.

Executive brief

Crabbox, a platform for managing remote development environments and leases, contains a security flaw where users with limited 'view-only' permissions can gain unauthorized control over active sessions. By exploiting this vulnerability, a low-privileged user can impersonate trusted system components to intercept or manipulate code, web-based remote desktop traffic (WebVNC), and network tunnels. This could lead to the theft of sensitive source code or the hijacking of active development sessions.

Technical details

A privilege escalation vulnerability exists in Crabbox due to insufficient access control checks in the ticket-minting endpoints. Specifically, the /v1/leases/:id/code/ticket, /v1/leases/:id/webvnc/ticket, and /v1/leases/:id/egress/ticket endpoints used a 'resolveLease' function that only verified lease visibility rather than manageability. An attacker with 'use' (visibility-only) permissions can send a POST request to these endpoints to obtain bridge-agent tickets. These tickets allow the holder to connect to WebSocket routes and impersonate or replace trusted lease-side bridges, effectively gaining control over the lease's code, VNC, or egress traffic. The issue is fixed in version 0.12.0 by requiring owner, manage, or admin access for these endpoints.

Affected products

  • openclaw Crabbox < 0.12.0

Timeline

  • 2026-05-11: patched: Fix merged into main branch
  • 2026-05-12: advisory: v0.12.0 release notes published
  • 2026-05-14: disclosed: CVE-2026-8629 published

References

Related threats