PT-2026-29230 · Openclaw · Openclaw
Tdjackey
·
Published
2026-03-13
·
Updated
2026-03-31
·
CVE-2026-32970
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.11
Description
The software contains a credential fallback issue. When local gateway authentication tokens (
gateway.auth.token) and passwords (gateway.auth.password) are unavailable, the system incorrectly falls back to remote credentials even when operating in local mode. This can occur due to misconfigured local authentication references, potentially allowing attackers to bypass local authentication restrictions and access the system using unintended credentials. The issue affects CLI and helper paths, causing them to select incorrect credential sources.Recommendations
Update to version 2026.3.11 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw