CVE-2026-56402
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
23/06/2026
Last modified:
23/06/2026
Description
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting approval response payloads without proper role validation.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM



