CVE-2026-32014

8.0

OpenClaw · OpenClaw

OpenClaw versions before 2026.2.26 contain a metadata spoofing vulnerability that allows authenticated attackers to bypass node command policies.

Executive summary

A critical authentication bypass vulnerability in OpenClaw allows attackers with paired node access to spoof metadata and execute restricted commands.

Vulnerability

This vulnerability involves a flaw in how the platform handles reconnect metadata, specifically the deviceFamily and reconnect platform fields, which are not bound to the device authentication signature. An attacker already authenticated as a paired node can leverage this weakness to spoof metadata and bypass established platform security policies.

Business impact

The ability to bypass node command policies poses a significant risk to the integrity and security of the managed network. Successful exploitation allows unauthorized execution of restricted commands, potentially leading to unauthorized system control or lateral movement. Given the CVSS score of 8.0, this represents a high-severity risk that requires immediate attention to prevent privilege escalation within the platform.

Remediation

Immediate Action: Update the OpenClaw package to version 2026.2.26 or later to ensure proper binding of metadata to the device authentication signature.

Proactive Monitoring: Review access logs for anomalous command patterns originating from paired nodes that attempt to access restricted functions or perform unauthorized administrative actions.

Compensating Controls: Implement strict network segmentation and monitor internal traffic between nodes to detect and block unauthorized command attempts from compromised or malicious nodes.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Organizations utilizing OpenClaw must prioritize updating to version 2026.2.26 immediately. This update addresses the core authentication flaw by enforcing proper signatures on metadata fields, effectively closing the spoofing vector. Failure to patch may allow attackers to escalate privileges and circumvent critical security controls, leading to potential compromise of the entire node infrastructure.

More OpenClaw CVEs

Sources

Originally found and disclosed by 76embiid21, per the CVE Program record.