Executive brief
OpenClaw is an AI assistant that performs automated tasks across different operating systems and platforms. When configuration is reloaded, the authentication state used to authorize new gateway connections may become stale, allowing attackers or unauthorized clients to bypass authentication checks and gain unauthorized access to the system.
Technical details
This vulnerability stems from a session state management issue (CWE-613: Insufficient Session Expiration) where the resolvedAuth closure retains stale cached authentication credentials across configuration reloads. When the configuration is reloaded, newly accepted gateway connections may continue using outdated authentication state rather than validating against the refreshed configuration. The attack vector is local with no authentication required beforehand. An attacker with local access can trigger a config reload and then establish new connections that inherit stale auth credentials, gaining unauthorized access. The vulnerability affects openclaw versions up to 2026.4.1 and is fixed in version 2026.4.8 (commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5).
Affected products
- OpenClaw OpenClaw <= 2026.4.1
Timeline
- 2026-04-09: disclosed
- 2026-04-08: patched: Fix available in version 2026.4.8