CVE.report search for "CVE-2026-39885"

Listed below are 50 relevant search results for "CVE-2026-39885" based on Vendor, Software, and CVE description

These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.

If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.

Search Results

CVE ID Vendor Software Description
CVE-2026-100653vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-suppl...
CVE-2026-100604ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organizat...
CVE-2026-100602ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A sig...
CVE-2026-100601ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile pre...
CVE-2026-100599OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The...
CVE-2026-100598OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction...
CVE-2026-100597OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell lo...
CVE-2026-100596OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp...
CVE-2026-100595OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows...
CVE-2026-100594OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allow...
CVE-2026-100593OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/act...
CVE-2026-100592OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutatio...
CVE-2026-100591OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could om...
CVE-2026-100590OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner exter...
CVE-2026-100589OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions t...
CVE-2026-100588OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control whe...
CVE-2026-100587OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation comman...
CVE-2026-100586OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-...
CVE-2026-100585OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code p...
CVE-2026-100584OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows...
CVE-2026-100583OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that a...
CVE-2026-100582OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do...
CVE-2026-100581OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the devic...
CVE-2026-100580OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-...
CVE-2026-100579OpenClaw (npm package 'openclaw') before 2026.7.1 incorrectly trusts requester provenance in message.action. In identity-bear...
CVE-2026-100578OpenClaw (npm package `openclaw`) before 2026.7.1 fails to restrict owner-only infrastructure tools exposed through the chat....
CVE-2026-100577OpenClaw versions before 2026.8.1 fail to validate video asset URLs returned by providers, allowing server-side requests to p...
CVE-2026-100576OpenClaw versions before 2026.8.1 contain a server-side request forgery vulnerability in browser wait predicates that allows ...
CVE-2026-100575OpenClaw Slack versions before 2026.8.1 fail to properly enforce sender allowlists in multi-person direct messages. Disallowe...
CVE-2026-100574OpenClaw (npm package 'openclaw') before 2026.8.1 contains a server-side request forgery vulnerability in its trusted-host DN...
CVE-2026-100573OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allows san...
CVE-2026-100572OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authenticat...
CVE-2026-100571OpenClaw (npm package 'openclaw') versions >= 2026.6.6 and < 2026.8.1 apply the SMS webhook invalid-request rate limit before...
CVE-2026-100570OpenClaw (npm package 'openclaw') versions >= 2026.3.28 and < 2026.8.1 allow an untrusted workspace .env file to set the CLOU...
CVE-2026-100569OpenClaw is an npm-distributed application. In versions >= 2026.4.25 and < 2026.8.1, the workspace environment-variable filte...
CVE-2026-100568OpenClaw versions before 2026.8.1 fail to properly restrict access to operator command cron jobs, allowing model-visible agen...
CVE-2026-100567OpenClaw is an agent gateway distributed as the npm package 'openclaw'. In versions >= 2026.4.5 and < 2026.8.1, the Gateway v...
CVE-2026-100566OpenClaw LINE versions before 2026.8.1 contain an access control vulnerability where group allowlist mode silently inherits D...
CVE-2026-100564OpenClaw versions before 2026.8.1 fail to neutralize spreadsheet formula characters in participant display names within atten...
CVE-2026-100563OpenClaw (npm package `openclaw`) before 2026.8.1 does not neutralize leading characters that spreadsheet applications interp...
CVE-2026-100562OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the sessions.create endpoint that allows o...
CVE-2026-100561OpenClaw (npm package 'openclaw') versions >= 2026.3.22 and < 2026.8.1 contain an approval-bypass flaw in the exec approval p...
CVE-2026-100560OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability where Allow Always approvals for exact comman...
CVE-2026-100559OpenClaw versions before 2026.8.1 contain a command parser vulnerability where escaped newlines confuse exec allowlist parsin...
CVE-2026-100558OpenClaw versions before 2026.8.1 contain a resource exhaustion vulnerability in the Gateway listener that allows unauthentic...
CVE-2026-100557OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in skill tool dispatch that fails to carry th...
CVE-2026-100556OpenClaw (npm package openclaw) versions >= 2026.5.2 and < 2026.8.1 contain an incorrect authorization vulnerability in Whats...
CVE-2026-100555OpenClaw is an npm-distributed gateway application. In versions >= 2026.7.1 and < 2026.8.1, Synology Chat attachment delivery...
CVE-2026-100554OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HTTP authorizatio...
CVE-2026-100553OpenClaw versions >= 2026.6.9 and < 2026.8.1 do not declare the native chatId parameter as a delivery target in the Feishu un...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report