Junglewise Threat Intelligence

OpenClaw gateway authentication bypass via Tailscale header spoofing

Severity: low · CVSS 3.1 · Published 2026-03-21

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a gateway application that secures HTTP routes with token and password authentication. When tokenless Tailscale authentication is enabled, a misconfiguration allows attackers on trusted networks to bypass these credentials entirely by spoofing Tailscale headers, gaining unauthorized access to protected HTTP routes. This weakens security boundaries even in supposedly trusted-network deployments.

Technical details

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes when the feature is intended only for Control UI websocket authentication. The vulnerability is an authentication bypass (CWE-290) caused by missing authorization scope gates in the gateway auth handler. An unauthenticated attacker on a trusted network can forge Tailscale forwarded headers to bypass token and password requirements. The fix adds an explicit allowTailscaleHeaderAuth gate (default false) and restricts tokenless auth to Control UI only, leaving HTTP gateway routes on standard token/password paths. Patched in version 2026.2.21.

Affected products

  • OpenClaw OpenClaw < 2026.2.21

Timeline

  • 2026-02-21: disclosed: Advisory GHSA-hff7-ccv5-52f8 published by OpenClaw
  • 2026-02-21: patched: Fix in commit 356d61aacfa5b0f1d5830716ec59d70682a3e7b8, planned release 2026.2.21
  • 2026-03-21: other: Duplicate advisory GHSA-qwmf-95r9-gx9x published
  • 2026-03-24: other: Duplicate advisory GHSA-qwmf-95r9-gx9x withdrawn

References

Related threats