CVE-2026-45223

HIGH

Crabbox < 0.9.0 Authentication Bypass via Admin Claim Injection

Title source: cna
STIX 2.1

Description

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin claim, allowing attackers to escalate privileges. An attacker with access to the shared non-admin token can craft a user-token payload with admin: true, sign it using HMAC-SHA256, and present it to admin-only coordinator routes to gain full coordinator admin access including lease visibility, pool state management, and forced release operations.

Scores

CVSS v3 8.8
EPSS 0.0008
EPSS Percentile 23.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-290
Status published
Products (2)
openclaw/crabbox < 0.9.0
openclaw/crabbox 46079f6de7f10cf61bc47efebd0c143a41664898
Published May 11, 2026
Tracked Since May 12, 2026