Executive brief
OpenClaw's Control UI is a web interface for managing and operating the gateway. When explicitly configured to allow insecure authentication and exposed over unencrypted HTTP, the Control UI bypasses critical security checks including device identity verification and pairing requirements. An attacker who intercepts credentials in transit or obtains them through other means can gain full administrative access to the gateway, enabling complete system compromise and control of the underlying platform.
Technical details
This vulnerability is an authentication bypass with cleartext transmission issues (CWE-285, CWE-319). When gateway.controlUi.allowInsecureAuth is explicitly enabled, the allowControlUiBypass flag suppresses two security checks in the WebSocket handshake handler: (1) HTTPS/localhost enforcement that normally blocks non-secure Control UI connections, and (2) device pairing requirements that gate access for new devices. This allows any client presenting a valid shared secret (token or password) to obtain full operator-level scopes over unencrypted HTTP without device identity registration or verification. Tokens are transmitted in plaintext. The vulnerability requires deliberate insecure configuration and credential exposure (plaintext transit or prior token leak). The fix, merged in commit 40a292619e1f2be3a3b1db663d7494c9c2dc0abf on 2026-02-20, corrects the allowControlUiBypass calculation to exclude the allowInsecureAuth flag, ensuring security checks are enforced even when insecure auth is configured.
Affected products
- OpenClaw openclaw <= 2026.2.19-2
Timeline
- 2026-03-03: disclosed: GHSA-3cvx-236h-m9fj published
- 2026-02-20: patched: Fix committed (40a292619e1f2be3a3b1db663d7494c9c2dc0abf)
- 2026-03-19: other: CVE-2026-32034 published in NVD
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-3cvx-236h-m9fj
- https://github.com/openclaw/openclaw/pull/20684
- https://github.com/openclaw/openclaw/commit/40a292619e1f2be3a3b1db663d7494c9c2dc0abf
- https://github.com/openclaw/openclaw
- https://www.vulncheck.com/advisories/openclaw-insecure-control-ui-authentication-over-plaintext-http