Junglewise Threat Intelligence

CVE-2026-43569: OpenClaw workspace provider auth auto-enable of untrusted plugins

CVE-2026-43569 · Severity: low · CVSS 3.1 · Published 2026-04-17

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a workspace collaboration platform that supports third-party plugins for authentication providers. A vulnerability in the non-interactive onboarding flow could allow an untrusted workspace plugin to auto-enable itself during authentication setup, potentially giving that malicious plugin unintended access to user credentials and workspace data.

Technical details

The vulnerability is a privilege escalation and plugin trust boundary violation (CWE-829: Inclusion of Functionality from Untrusted Control Sphere). During non-interactive onboarding, the application could select a provider auth choice that was shadowed by an untrusted workspace plugin, causing that untrusted plugin to auto-enable during auth configuration. The attack requires user interaction to initiate onboarding but does not require authentication. The fix prioritizes trusted provider origins for auth choices and excludes untrusted workspace choices unless explicitly enabled by the user. Patches are available in version 2026.4.9 and later.

Affected products

  • OpenClaw openclaw before 2026.4.9

Timeline

  • 2026-04-17: disclosed
  • 2026-04-09: patched: Fixed in version 2026.4.9

References

Related threats