Junglewise Threat Intelligence

CVE-2026-32970: OpenClaw credential fallback bypass in local auth SecretRefs

CVE-2026-32970 · Severity: low · CVSS 3.1 · Published 2026-03-31

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a tool used for managing gateway credentials and authentication. A security flaw in certain versions allows the system to incorrectly fall back to remote credentials when local authentication settings are misconfigured or unavailable. This could allow an attacker with local access to bypass intended security boundaries and potentially access sensitive information by forcing the application to use an incorrect credential source.

Technical details

A credential fallback vulnerability exists in OpenClaw's local-mode helper logic (CWE-636). The root cause is that the application treats configured but unavailable 'gateway.auth.token' and 'gateway.auth.password' SecretRefs as if they were entirely unset. This logic error allows the system to fall back to 'gateway.remote.*' credentials even when local mode is active. A local attacker with low privileges can exploit this misconfiguration to cause CLI and helper paths to select incorrect credential sources, potentially bypassing local authentication boundaries. The issue is resolved in version 2026.3.11 by tracking configuration status independently of resolution success.

Affected products

  • OpenClaw OpenClaw < 2026.3.11

Timeline

  • 2026-03-12: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: NVD publication date
  • 2026-03-11: patched: Version 2026.3.11 released

References

Related threats