Junglewise Threat Intelligence

OpenClaw identity header spoofing in trusted-proxy deployments

Severity: high · CVSS 7.7 · Published 2026-07-02

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a gateway and plugin platform, contains a security flaw in how it handles identity information when used with certain proxy configurations. An attacker on the same host could forge identity headers to impersonate authorized operators, potentially gaining unauthorized access to sensitive operations or data. This risk is highest in environments where multiple untrusted users share the same server.

Technical details

A vulnerability in OpenClaw's Gateway component allows for authentication bypass via spoofing when deployed in a same-host trusted-proxy configuration. The system fails to properly validate that identity headers are originating exclusively from the trusted proxy, allowing a local caller on the same host to supply forged headers. If the attacker can reach the proxy-facing Gateway port, they can assume the identity of an operator associated with those headers. This issue is tracked as CWE-290 and CWE-287. Users should update to version 2026.5.18 or later and ensure that trusted-proxy ingress is firewalled from direct same-host access.

Affected products

  • openclaw openclaw < 2026.5.18

Timeline

  • 2026-05-28: disclosed: Initial disclosure by reporter
  • 2026-05-28: patched: First stable patched version 2026.5.18 released
  • 2026-07-02: advisory: GitHub Advisory published

References

Related threats