PT-2026-37024 · Openclaw · Openclaw
Peng Zhou
·
Published
2026-04-17
·
Updated
2026-05-05
·
CVE-2026-43569
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.4.9
Description
An authentication bypass allows untrusted workspace plugins to be automatically enabled during non-interactive onboarding when provider authentication choices are shadowed. This occurs because the system could select a provider authentication choice shadowed by an untrusted workspace plugin, enabling the plugin during authentication setup without explicit user consent.
Recommendations
Update to version 2026.4.9 or newer.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw