Junglewise Threat Intelligence

CVE-2026-41393: OpenClaw: macOS Tailnet DNS Spoofing & Credential Exfiltration

CVE-2026-41393 · Severity: high · CVSS 4 · Published 2026-04-03

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a network management tool used to configure and control macOS systems within private networks. A bug in its wide-area discovery mechanism allows an attacker on the same network to impersonate a trusted gateway and intercept DNS traffic, potentially stealing operator credentials. Exploitation requires the attacker to be on the same network, have access to a trusted certificate authority, and trick a user into connecting to a malicious endpoint.

Technical details

The vulnerability is a DNS spoofing and credential exfiltration issue in OpenClaw's macOS wide-area gateway discovery mechanism (CWE-346: Origin Validation Error, CWE-350: Reliance on Untrusted Input in Security Decision). The root cause is that the discovery process accepts arbitrary Tailnet peers as DNS authorities without proper validation, allowing an attacker to redirect DNS queries and harvest credentials. An attacker must be positioned on the same Tailnet (private network), have a CA-trusted endpoint available, and the user must select the attacker's malicious gateway. The fix, released in version 2026.3.31, involves implementing MagicDNS for gateway discovery to prevent arbitrary peer acceptance. All versions prior to 2026.3.28 are affected.

Affected products

  • OpenClaw OpenClaw <=2026.3.28

Timeline

  • 2026-04-03: disclosed
  • 2026-03-31: patched: Fix released in version 2026.3.31

References

Related threats