PT-2026-26746 · Openclaw · Openclaw

Aether Ai

·

Publicado

2026-03-03

·

Atualizado

2026-05-18

·

CVE-2026-32897

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22
Description The software reuses the gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset. This creates a dual-use of authentication secrets across security domains. An attacker with access to system prompts sent to third-party model providers can derive the gateway authentication token from the hash outputs, potentially compromising gateway authentication security.
Recommendations Update to version 2026.2.22 or later.

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32897
GHSA-8MR2-F9WF-HCFQ
GHSA-V6X2-2QVM-6GV8

Produtos afetados

Openclaw