Executive brief
OpenClaw is a security tool used to protect shared authentication access. An attacker can craft a fake device token to bypass rate limiting controls that normally protect against brute-force attacks on weak shared passwords. This allows an attacker to rapidly attempt multiple password guesses without being throttled, increasing the risk of unauthorized access if weak credentials are in use.
Technical details
The vulnerability exists in OpenClaw's mixed WebSocket authentication flow, where attackers can use fake device tokens to circumvent rate limiting controls (CWE-799: Improper Rate Limiting). The attack requires network access to the authentication endpoint but no authentication credentials to initiate. By submitting requests with crafted device tokens, an attacker can bypass per-request or per-device rate limits and conduct brute-force attacks against shared authentication secrets. The practical risk is limited to deployments using weak shared passwords; strong shared tokens remain resistant to brute-force attempts. A patch is available in version 2026.3.31 and later.
Affected products
- OpenClaw OpenClaw <= 2026.3.28
Timeline
- 2026-03-31: disclosed
- 2026-03-31: patched: Version 2026.3.31 released with fix
- 2026-04-24: advisory