Metrics
Affected Vendors & Products
Thu, 14 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openclaw
Openclaw crabbox |
|
| Vendors & Products |
Openclaw
Openclaw crabbox |
Thu, 14 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a shared token to bypass authorization checks and access owner/org-scoped lease operations belonging to victim accounts. | |
| Title | Crabbox < v0.12.0 Authentication Bypass via Header Spoofing | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T19:50:07.817Z
Reserved: 2026-05-14T18:39:14.316Z
Link: CVE-2026-8621
Updated: 2026-05-14T19:37:44.738Z
Status : Received
Published: 2026-05-14T19:16:39.517
Modified: 2026-05-14T19:16:39.517
Link: CVE-2026-8621
No data.
OpenCVE Enrichment
Updated: 2026-05-14T20:45:28Z