PT-2026-37024 · Openclaw · Openclaw

Peng Zhou

·

Published

2026-04-17

·

Updated

2026-05-05

·

CVE-2026-43569

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.4.9
Description An authentication bypass allows untrusted workspace plugins to be automatically enabled during non-interactive onboarding when provider authentication choices are shadowed. This occurs because the system could select a provider authentication choice shadowed by an untrusted workspace plugin, enabling the plugin during authentication setup without explicit user consent.
Recommendations Update to version 2026.4.9 or newer.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-43569
GHSA-939R-RJ45-G2RJ

Affected Products

Openclaw