PT-2026-29230 · Openclaw · Openclaw

·

CVE-2026-32970

·

Published

2026-03-13

·

Updated

2026-07-25

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.11
Description The software contains a credential fallback issue. When local gateway authentication tokens (gateway.auth.token) and passwords (gateway.auth.password) are unavailable, the system incorrectly falls back to remote credentials even when operating in local mode. This can occur due to misconfigured local authentication references, potentially allowing attackers to bypass local authentication restrictions and access the system using unintended credentials. The issue affects CLI and helper paths, causing them to select incorrect credential sources.
Recommendations Update to version 2026.3.11 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32970
GHSA-QVR7-G57C-MRC7
GHSA-VM29-7MQ3-9JRG

Affected Products

Openclaw