Junglewise Threat Intelligence

CVE-2026-3690: OpenClaw authentication bypass in canvas endpoints

CVE-2026-3690 · Severity: high · CVSS 7.4 · Published 2026-04-11

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

A security flaw in OpenClaw allows unauthorized individuals to bypass login requirements for canvas endpoints. This could allow an attacker to gain unauthorized access to the system and its data without needing a valid username or password. The issue affects the core security of the platform, potentially leading to data theft or unauthorized administrative actions.

Technical details

An authentication bypass vulnerability exists in OpenClaw due to the improper implementation of the authentication function for canvas endpoints. Specifically, the application relies on IP addresses for authentication (CWE-291), which can be spoofed or manipulated. A remote, unauthenticated attacker can exploit this flaw to gain unauthorized access to protected system resources. The vulnerability is addressed in version 2026.2.19. Exploitation requires certain network conditions (AC:H) but no user interaction.

Affected products

  • OpenClaw OpenClaw versions up to (excluding) 2026.2.19

Timeline

  • 2026-02-20: disclosed: Vulnerability reported to vendor
  • 2026-03-30: patched: Coordinated public release of advisory and update
  • 2026-04-11: advisory: NVD publication date

References

Related threats