PT-2026-26386 · Openclaw · Openclaw

Tdjackey

·

Published

2026-03-19

·

Updated

2026-03-19

·

CVE-2026-32004

CVSS v3.1

6.5

Medium

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classification due to canonicalization depth mismatch between auth-path classification and route-path canonicalization. Attackers can bypass plugin route authentication checks by submitting deeply encoded slash variants such as multi-encoded %2f to access protected /api/channels endpoints.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2026-32004

Affected Products

Openclaw