← Vulnerability feed

Vulnerability record · CVE-2026-28472 · published 5 March 2026

CVE-2026-28472: Openclaw missing authentication for critical function vulnerability

Openclaw · Openclaw

OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway without providing device identity or pairing by exploiting the presence check instead of validation, potentially gaining operator access in vulnerable deployments.

9.2 CVSS 4.0 Critical EPSS 0.63% · top 51.9% CWE-306 · Missing authentication for critical function
9.2CVSS 4.0 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway without providing device identity or pairing by exploiting the presence check instead of validation, potentially gaining operator access in vulnerable deployments.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-28472 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-30741Openclaw code injection vulnerabilityA remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt…EPSS 1.2%9.4CVE-2026-33579Openclaw incorrect authorization vulnerabilityOpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into th…EPSS 0.51%9.4CVE-2026-32978Openclaw incorrect authorization vulnerabilityOpenClaw before 2026.3.11 contains an approval integrity vulnerability where system.run approvals fail to bind mutable file operands for certain scri…EPSS 0.32%9.4CVE-2026-32922Openclaw vulnerabilityOpenClaw before 2026.3.11 contains a privilege escalation vulnerability in device.token.rotate that allows callers with operator.pairing scope to min…EPSS 0.69%9.4CVE-2026-22172Openclaw missing authorization vulnerabilityOpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password…EPSS 0.56%9.4CVE-2026-28466Openclaw incorrect authorization vulnerabilityOpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke par…EPSS 0.67%9.3CVE-2026-43534Openclaw insufficient verification of data authenticity vulnerabilityOpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Atta…EPSS 0.30%9.3CVE-2026-32987Openclaw authentication bypass by capture-replay vulnerabilityOpenClaw before 2026.3.13 allows bootstrap setup codes to be replayed during device pairing verification in src/infra/device-bootstrap.ts. Attackers …EPSS 0.61%

Source: NIST National Vulnerability Database (record CVE-2026-28472), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.