clawsmith.com/signal/cve-2026-45223-crabbox-coordinator-admin-bypass
⚠ IssueWide OpenLive
CVE-2026-45223: Crabbox Coordinator Authentication Bypass Lets Non-Admin Escalate to Full Admin (CVSS 8.8)
Crabbox (OpenClaw multi-instance coordinator) before 0.9.0 has an authentication bypass in verifyUserToken() that fails to reject admin claims in user tokens. Attackers with shared non-admin token access can sign admin:true payloads via HMAC-SHA256 to gain full coordinator admin access.
Product Idea from this Signal
A reverse proxy that locks OpenClaw gateway configuration against model-driven mutation by enforcing an allowlist of immutable protected settings
8 ▲SECURITYREVERSE-PROXYOPEN-SOURCEDEVTOOL
CompetitiveView Opportunity →
Social Proof 2 sources
Frequently Asked Questions
Virality Score
0
across 0 platforms
Details
Signalissue
Ecosystem—
Sources2
Platforms0
Updated26d ago
Trend→ stable
Top ideas
All ideas →Related signals
All signals →