PT-2026-35800 · Openclaw · Openclaw

Kexna

·

Published

2026-04-09

·

Updated

2026-04-29

·

CVE-2026-42421

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.8
Description A session management issue exists where WebSocket sessions persist after shared gateway token rotation. This allows attackers to maintain unauthorized access to WebSocket connections because the system fails to disconnect sessions associated with the rotated shared token.
Recommendations Update to version 2026.4.8.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42421
GHSA-5H3F-885M-V22W

Affected Products

Openclaw