Junglewise Threat Intelligence

CVE-2026-28472: OpenClaw gateway authentication bypass via incomplete token validation

CVE-2026-28472 · Severity: low · CVSS 3.1 · Published 2026-02-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a control platform used to manage network infrastructure and devices. The gateway component has a flaw in its WebSocket connection handshake that could allow an attacker to bypass device identity checks and gain unauthorized operator access if the gateway is reachable from a network they can access, particularly in setups using Tailscale authentication.

Technical details

The vulnerability exists in src/gateway/server/ws-connection/message-handler.ts where the device-identity requirement is bypassed based on the presence of a non-empty connectParams.auth.token, rather than validating that the token has been properly authenticated via shared-secret validation. An attacker with network access to the gateway WebSocket (e.g., within a Tailscale network) can send a connection request with an unvalidated auth.token to skip device identity/pairing checks. Depending on version and configuration, this could grant operator-level access without proper device provisioning. The fix requires that device-identity skipping only succeeds after validated shared-secret authentication, and Tailscale-authenticated connections without validated secrets must provide device identity. Patched in version 2026.2.2 and later.

Affected products

  • OpenClaw openclaw <=2026.2.1

Timeline

  • 2026-02-14: disclosed
  • 2026-02-17: patched: version 2026.2.2
  • 2026-02-17: advisory

References

Related threats