Two high-severity vulnerabilities disclosed in VNC-related software allowed local attackers to access or interfere with graphical sessions without proper authorization. OpenClaw versions before 2026.2.21 were affected by CVE-2026-32064, a missing-authentication flaw in the sandbox browser noVNC observer entrypoint. The issue stemmed from x11vnc being launched without authentication, enabling anyone on the host loopback interface to connect to the exposed noVNC port and observe or interact with the sandbox browser. The bug was classified as CWE-306 and carried a CVSS 3.1 score reflecting high confidentiality and integrity impact.
A separate issue, CVE-2026-34352, affected TigerVNC before version 1.16.2 in Image.cxx within x0vncserver. Incorrect permissions could let other local users observe or manipulate screen contents and potentially crash an application, leading to a privilege-escalation scenario. The flaw was classified as CWE-732 and assigned a CVSS 3.1 vector indicating high confidentiality impact with lower integrity and availability effects. Fixes and advisories were published through the projects' GitHub repositories, release channels, and security mailing lists.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-34352 was publicly published for TigerVNC before version 1.16.2. The vulnerability was classified under CWE-732 and assigned a high-severity CVSS v3.1 score reflecting significant confidentiality impact.
TigerVNC released version 1.16.2 to fix a privilege escalation vulnerability affecting earlier versions. The issue involved incorrect permissions in x0vncserver that exposed screen contents and allowed limited manipulation or application crashes by local users.
TigerVNC vulnerability CVE-2026-34352 was received by cve@mitre.org on March 26, 2026. The flaw in Image.cxx within x0vncserver could let other local users observe or manipulate screen contents or crash an application because of incorrect permissions.
The OpenClaw vulnerability was publicly documented as CVE-2026-32064, affecting versions prior to 2026.2.21. The issue was classified as CWE-306 and described as allowing host-local attackers to observe or interact with sandbox browser sessions without credentials.
OpenClaw addressed a missing authentication issue in the sandbox browser entrypoint for noVNC observer sessions in version 2026.2.21. The flaw allowed unauthenticated access to the VNC interface because x11vnc was launched without authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.