LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32920

CVE-2026-32920 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 31, 2026

OpenClaw - Remote Code Execution

Published: March 31, 2026Updated: March 31, 2026Remote Exploitable

Overview

OpenClaw < 2026.3.12 contains a remote code execution caused by automatic loading of untrusted plugins from .OpenClaw/extensions/, letting attackers execute arbitrary code when running OpenClaw from crafted directories, exploit requires attacker to place malicious plugins in cloned repositories.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 5.3%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary code remotely by placing malicious plugins, potentially leading to full system compromise.

Mitigation

Update to version 2026.3.12 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 31, 2026

šŸ”“ CVE-2026-32920 - Critical (9.8) OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in c... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32920/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 31, 2026

šŸ”“ CVE-2026-32920 - Critical (9.8) OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in c... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-32920/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-32920
Severity
Critical
CVSS Score
9.8
Type
unrestricted_file_upload
Status
new
EPSS
5.3%
Social Posts
2

CWE

  • CWE-829

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

5.3%Probability of exploitation in the next 30 days