Junglewise Threat Intelligence

OpenClaw authentication bypass in remote onboarding

Severity: low · CVSS 3.1 · Published 2026-04-24

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a command-line interface tool used for remote gateway onboarding and management. The vulnerability allows attackers to intercept the onboarding process by spoofing discovery endpoints, capturing credentials and potentially redirecting connections to malicious gateways without user verification. This could lead to credential theft and unauthorized access to gateway infrastructure.

Technical details

OpenClaw before version 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component (src/commands/onboard-remote.ts) that fails to validate discovered gateway endpoints before persisting connection details. The vulnerability is classified as improper resource validation (CWE-346). An attacker with adjacent network access can spoof discovery endpoints to redirect the onboarding process toward a malicious gateway, capturing credentials or intercepting traffic. No user privileges are required, though user interaction (passive) with the onboarding process is necessary. The vulnerability was patched in version 2026.3.28 via commit d6affb17d8, which adds explicit trust confirmation before saving discovered gateway configurations.

Affected products

  • OpenClaw OpenClaw <= 2026.3.24

Timeline

  • 2026-03-29: disclosed
  • 2026-03-28: patched: Version 2026.3.28 contains the fix

References

Related threats