Skip to main content
// menu
×
>
Loading…
// threat_lookup
×
☰
INTELLIGENCE ROOM
// cybersoc_platform
Dashboard
CVE/RCE
APT
News
Reports
Pulse
SOON
Graph
SOON
Market
SOON
Playback
SOON
NOMINAL
0
Sign in
Join →
CVE-2026-44118 — OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-g — CVE Database · The Intelligence Room