Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

Vulnerabilidades

Con el objetivo de informar, advertir y ayudar a los profesionales sobre las últimas vulnerabilidades de seguridad en sistemas tecnológicos, ponemos a disposición de los usuarios interesados en esta información una base de datos con información en castellano sobre cada una de las últimas vulnerabilidades documentadas y conocidas.

Este repositorio con más de 75.000 registros esta basado en la información de NVD (National Vulnerability Database) – en función de un acuerdo de colaboración – por el cual desde INCIBE realizamos la traducción al castellano de la información incluida. En ocasiones este listado mostrará vulnerabilidades que aún no han sido traducidas debido a que se recogen en el transcurso del tiempo en el que el equipo de INCIBE realiza el proceso de traducción.

Se emplea el estándar de nomenclatura de vulnerabilidades CVE (Common Vulnerabilities and Exposures), con el fin de facilitar el intercambio de información entre diferentes bases de datos y herramientas. Cada una de las vulnerabilidades recogidas enlaza a diversas fuentes de información así como a parches disponibles o soluciones aportadas por los fabricantes y desarrolladores. Es posible realizar búsquedas avanzadas teniendo la opción de seleccionar diferentes criterios como el tipo de vulnerabilidad, fabricante, tipo de impacto entre otros, con el fin de acortar los resultados.

Mediante suscripción RSS o Boletines podemos estar informados diariamente de las últimas vulnerabilidades incorporadas al repositorio.

CVE-2026-53813

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from unintended local locations, potentially executing malicious code or accessing sensitive data.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026

CVE-2026-53812

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to private-network targets via action-triggered redirects and subsequently read restricted page content using browser evaluation capabilities.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/06/2026

CVE-2026-53811

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026

CVE-2026-53810

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026

CVE-2026-53817

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient locality-derived trust validation to convert temporary shared access into persistent administrative credentials that survive token rotation.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026

CVE-2026-53816

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send crafted node.event messages to the gateway, steering target sessions into exec-event paths that expose capabilities the reduced node surface should not provide.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026

CVE-2026-50005

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Brickcom cameras<br /> ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026

CVE-2026-50245

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026

CVE-2026-53809

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select bundled tool access outside intended provider policy restrictions when the affected feature is enabled.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/06/2026

CVE-2026-53808

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affected apply path to apply workshop changes before the expected approval step, potentially modifying configurations without proper authorization.
Gravedad CVSS v4.0: MEDIA
Última modificación:
12/06/2026

CVE-2026-53807

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026

CVE-2026-53806

Fecha de publicación:
11/06/2026
Idioma:
Inglés
*** Pendiente de traducción *** OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without intended allowlist validation, potentially enabling unauthorized command execution when the affected feature is enabled.
Gravedad CVSS v4.0: ALTA
Última modificación:
12/06/2026