CVE-2026-43569
8.8OpenClaw · OpenClaw
OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled.
Executive summary
An authentication bypass vulnerability in OpenClaw before version 2026.4.9 allows attackers to auto-enable malicious workspace plugins during non-interactive onboarding, resulting in total system compromise.
Vulnerability
This is an inclusion of functionality from an untrusted control sphere vulnerability (CWE-829) triggered during non-interactive onboarding when provider authentication choices are shadowed, requiring unauthenticated access with low attack complexity and user interaction.
Business impact
A successful exploitation of this vulnerability can lead to complete system compromise, giving attackers unauthorized control over affected environments. With a CVSS score of 8.8, the high severity reflects the potential for total loss of confidentiality, integrity, and availability within the affected scope, threatening organizational operations and data security.
Remediation
Immediate Action: Update the OpenClaw package to version 2026.4.9 or later immediately.
Proactive Monitoring: Monitor access logs and onboarding workflows for anomalous plugin activation events and unauthorized workspace modifications.
Compensating Controls: Restrict non-interactive onboarding procedures and enforce strict perimeter controls to prevent untrusted network interactions until the software is updated.
Exploitation status
Public Exploit Available: No - there is no confirmed public exploit in the available data.
Analyst recommendation
Given the high severity and the potential for total impact on system integrity and confidentiality, administrators must treat this vulnerability with urgency. Apply the primary remediation by updating the affected software immediately to version 2026.4.9 to eliminate the authentication bypass risk.
More OpenClaw CVEs
Sources
Originally found and disclosed by Peng Zhou (@zpbrent), per the CVE Program record.
- GitHub Security Advisory (GHSA-939r-rj45-g2rj) Vendor advisory
- Patch Commit Patch commit
- VulnCheck Advisory: OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider Auth Third-party advisory