PT-2026-23559 · Openclaw · Openclaw

Troy Cusolle

·

Published

2026-02-13

·

Updated

2026-03-11

·

CVE-2026-28485

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.1.5 through 2026.2.11
Description The software does not enforce mandatory authentication on the /agent/act browser-control HTTP route. This allows unauthorized local callers to invoke privileged operations. Remote attackers on the local network or local processes can execute arbitrary browser-context actions and access sensitive in-session data by sending requests to unauthenticated endpoints.
Recommendations Update to version 2026.2.12 or later.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2026-06353
CVE-2026-28485
GHSA-QPJJ-47VM-64PJ

Affected Products

Openclaw