PT-2026-26746 · Openclaw · Openclaw

Aether Ai

·

Published

2026-03-03

·

Updated

2026-05-18

·

CVE-2026-32897

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.22
Description The software reuses the gateway.auth.token as a fallback hash secret for owner-ID prompt obfuscation when commands.ownerDisplay is set to hash and commands.ownerDisplaySecret is unset. This creates a dual-use of authentication secrets across security domains. An attacker with access to system prompts sent to third-party model providers can derive the gateway authentication token from the hash outputs, potentially compromising gateway authentication security.
Recommendations Update to version 2026.2.22 or later.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2026-32897
GHSA-8MR2-F9WF-HCFQ
GHSA-V6X2-2QVM-6GV8

Affected Products

Openclaw