PT-2026-29230 · Openclaw · Openclaw

·

CVE-2026-32970

·

Publicado

2026-03-13

·

Atualizado

2026-07-25

CVSS v3.1

3.3

Baixa

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.11
Description The software contains a credential fallback issue. When local gateway authentication tokens (gateway.auth.token) and passwords (gateway.auth.password) are unavailable, the system incorrectly falls back to remote credentials even when operating in local mode. This can occur due to misconfigured local authentication references, potentially allowing attackers to bypass local authentication restrictions and access the system using unintended credentials. The issue affects CLI and helper paths, causing them to select incorrect credential sources.
Recommendations Update to version 2026.3.11 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32970
GHSA-QVR7-G57C-MRC7
GHSA-VM29-7MQ3-9JRG

Produtos afetados

Openclaw