{"id":"CVE-2026-8621","aliases":["GHSA-4g9m-rffv-h6wq","GO-2026-5120"],"url":"https://o3.security/vulnerability/CVE-2026-8621","summary":"Crabbox < v0.12.0 Authentication Bypass via Header Spoofing","details":"Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a shared token to bypass authorization checks and access owner/org-scoped lease operations belonging to victim accounts.","published":"2026-05-14T18:46:43.230Z","modified":"2026-08-07T11:51:34.056275974Z","cvss":null,"epss":{"score":0.00361,"percentile":0.28869,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/openclaw/crabbox","fixedVersion":"0.12.0"}],"fix":{"url":"https://github.com/openclaw/crabbox/commit/b657323f1d1c954cefc8444571fa6c45a8896e7f","label":"openclaw/crabbox@b657323"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8621.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/crabbox/releases/tag/v0.12.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8621"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/crabbox-authentication-bypass-via-header-spoofing"},{"type":"REPORT","url":"https://github.com/openclaw/crabbox/pull/70"},{"type":"FIX","url":"https://github.com/openclaw/crabbox/commit/b657323f1d1c954cefc8444571fa6c45a8896e7f"},{"type":"PACKAGE","url":"https://github.com/openclaw/crabbox"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:34.056275974Z"}}