Privilege Escalation Vulnerability in NanoClaw by NanoCo
CVE-2026-56693

6.8MEDIUM

Key Information:

Vendor

Nanocoai

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-56693?

NanoClaw before version 2.1.17 is susceptible to a privilege escalation vulnerability within the create_agent delivery-action handler. The flaw allows confined agent containers to execute privileged central-database writes without proper host-side authorization checks. Consequently, this can lead to the creation of arbitrary agent groups, container configurations, and destinations, circumventing established confinement boundaries.

Affected Version(s)

nanoclaw 0 < 2.1.17

nanoclaw 2.1.17

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.