Security Advisory

CVE-2026-56693

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-23 15:35:19
Last updated 2026-07-14 21:34:16
Assigner VulnCheck
CVSS score 6.8
State PUBLISHED

Description

NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent groups, container configurations, and destinations, escalating beyond their intended confinement boundary.