CVE-2026-28472

8.1

OpenClaw · OpenClaw

OpenClaw is vulnerable to a device identity check bypass within the gateway websocket connect handshake due to missing authentication for critical functions.

Executive summary

An unauthenticated device identity check bypass vulnerability in OpenClaw allows remote attackers to compromise critical system functions.

Vulnerability

This vulnerability (CWE-306) occurs because the application fails to perform necessary authentication during the gateway websocket handshake process, allowing unauthenticated remote attackers to bypass identity verification.

Business impact

Successful exploitation allows an unauthenticated attacker to interact with sensitive gateway functions, potentially leading to unauthorized system access or control. Given the CVSS score of 8.1, this represents a high-severity risk that could result in significant operational disruption and data integrity loss.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.2.2 or later to apply the necessary authentication checks.

Proactive Monitoring: Monitor websocket traffic for unexpected connection patterns or unauthorized handshake attempts originating from untrusted sources.

Compensating Controls: Deploy a Web Application Firewall (WAF) or API gateway to filter and validate incoming websocket traffic, blocking requests that do not adhere to expected authentication protocols.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this flaw necessitates immediate attention. Organizations utilizing OpenClaw must prioritize updating to version 2026.2.2 to close the authentication gap and prevent unauthorized access to the gateway infrastructure.

More OpenClaw CVEs