PT-2026-31769 · Openclaw · Openclaw

Smaeljaish771

·

Published

2026-03-26

·

Updated

2026-04-10

·

CVE-2026-35634

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.23
Description OpenClaw contains an authentication bypass in the Canvas gateway. The authorizeCanvasRequest() function unconditionally allows local-direct requests without validating bearer tokens or canvas capabilities. This allows attackers to send unauthenticated HTTP and WebSocket requests to Canvas routes, bypassing authentication and gaining unauthorized access.
Recommendations Update to version 2026.3.23 or later.

Fix

Improper Authentication

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2026-35634
GHSA-6MQC-JQH6-X8FC
GHSA-9GVX-VJ57-VQQX

Affected Products

Openclaw