PT-2026-34764 · Openclaw · Openclaw
Kexna
·
Published
2026-04-03
·
Updated
2026-04-25
·
CVE-2026-41333
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.31
Description
An authentication rate limiting bypass allows attackers to circumvent shared authentication protections by using fake device tokens. By exploiting the mixed WebSocket authentication flow, attackers can bypass rate limiting controls to perform brute force attacks against weak shared passwords.
Recommendations
Update to version 2026.3.31.
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw