Junglewise Threat Intelligence

OpenClaw identity header authentication bypass in trusted-proxy

Severity: high · CVSS 7.7 · Published 2026-06-13

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a cloud-native orchestration platform that uses identity headers to authenticate requests from trusted proxies. In affected versions, an attacker with local access to the proxy-facing Gateway port can forge these identity headers to impersonate an operator and escalate their privileges. This could allow unauthorized actions depending on the operator's configuration and whether untrusted users can reach that network path.

Technical details

This is an authentication bypass vulnerability (CWE-290: Authentication Bypass by Spoofing) affecting the trusted-proxy identity header validation mechanism in OpenClaw. The root cause is insufficient validation of identity headers in same-host deployments, allowing local callers to forge headers normally reserved for the trusted proxy. The attack requires local network access to the proxy-facing Gateway port but no authentication credentials or user interaction. Successful exploitation allows an attacker to assume operator identity and escalate privileges within the affected OpenClaw instance. The vulnerability is patched in version 2026.5.18. Mitigation includes binding trusted-proxy ingress behind a firewall and disabling the feature when not needed.

Affected products

  • OpenClaw OpenClaw < 2026.5.18

Timeline

  • 2026-06-13: disclosed: Advisory GHSA-3qg8-hq7j-jj33 published (duplicate)
  • 2026-05-28: disclosed: Original advisory GHSA-rggc-m335-3wvj published
  • 2026-08-28: other: GHSA-3qg8-hq7j-jj33 withdrawn as duplicate of GHSA-rggc-m335-3wvj
  • 2026-05-18: patched: Version 2026.5.18 released with patch

References