CVE-2026-41342
7.3OpenClaw · OpenClaw
An authentication bypass vulnerability in OpenClaw allows unauthenticated attackers to spoof discovery endpoints, redirecting traffic and capturing credentials during the remote onboarding process.
Executive summary
OpenClaw is vulnerable to an authentication bypass flaw that permits unauthenticated attackers to intercept sensitive onboarding traffic and credentials.
Vulnerability
This is an origin validation error (CWE-346) located in the remote onboarding component. It allows unauthenticated remote attackers to manipulate discovery endpoints without explicit trust, leading to credential exfiltration.
Business impact
Successful exploitation poses a significant risk to organizational security, as it allows for the theft of gateway credentials and the interception of sensitive network traffic. With a CVSS score of 7.3, this high-severity vulnerability could lead to unauthorized network access and potential lateral movement within the environment.
Remediation
Immediate Action: Update the OpenClaw package to version 2026.3.28 or later to resolve the origin validation flaw.
Proactive Monitoring: Review network access logs for unusual discovery requests or connections to unauthorized gateways during the onboarding process.
Compensating Controls: Implement strict network segmentation and ensure that onboarding traffic is restricted to known, trusted gateways via firewall rules.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the potential for credential theft and traffic interception, this vulnerability presents a serious security risk to the integrity of onboarding workflows. IT and security teams should prioritize upgrading to version 2026.3.28 immediately to eliminate the attack vector and ensure secure gateway communications.
More OpenClaw CVEs
Sources
Originally found and disclosed by Nathan (@nexrin), KeenSecurityLab, per the CVE Program record.