Privilege Escalation in NanoClaw Affects Admin Privileges
CVE-2026-56694
5.3MEDIUM
What is CVE-2026-56694?
NanoClaw versions prior to 2.1.0 contain a vulnerability that allows scoped admins to bypass access controls during the channel-registration approval process. The function responsible for handling channel approval responses does not adequately validate admin privileges, leading to the possibility of submitting forged or outdated connect callback values. This flaw can enable unauthorized access to unapproved messaging channels, exposing restricted agent group activities to unauthorized observers or allowing them to exert control over such groups.
Affected Version(s)
nanoclaw 0 < 2.1.0
nanoclaw 2.1.0
