Unrated severityNVD Advisory· Published Jun 23, 2026· Updated Jun 23, 2026
NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System Action
CVE-2026-56693
Description
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent groups, container configurations, and destinations, escalating beyond their intended confinement boundary.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/nanocoai/nanoclaw/commit/ac37ecbfd6b9d14fdfa1598a6412a8ffdbeaef45mitrepatch
- www.vulncheck.com/advisories/nanoclaw-privilege-escalation-via-unauthorized-create-agent-system-actionmitrethird-party-advisory
- github.com/nanocoai/nanoclaw/pull/2720mitreissue-tracking
News mentions
0No linked articles in our index yet.