216.73.217.6

CVE-2026-32025

· Published 19/03/2026 22:16 · Modified 20/03/2026 13:39

Labels: CVE-2026-32025 2026-03-19CVE-2026-32025CWE-307[email protected]

Essential information

Published
19/03/2026 22:16
Modified
20/03/2026 13:39
Author
Creator
CVSS
7.5 HIGH (v3) 7.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

OpenClaw versions prior to 2026.2.25 contain an authentication hardening gap in browser-origin WebSocket clients that allows attackers to bypass origin checks and auth throttling on loopback deployments. An attacker can trick a user into opening a malicious webpage and perform password brute-force attacks against the gateway to establish an authenticated operator session and invoke control-plane methods.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
openclaw / openclaw cpe:2.3:a:openclaw:openclaw:<2026.2.25:*:*:*:*:*:*:*

References