OpenClaw Authentication Bypass Vulnerability in Plugin Channel Endpoints

Vulnerability

An authentication bypass vulnerability has been identified in OpenClaw versions prior to 2026.2.26 in the server-http component. This vulnerability arises in gateway authentication for plugin channel endpoints, due to a mismatch in path canonicalization between the gateway guard and the plugin handler routing. Attackers can exploit this by sending requests with alternative path encodings, allowing them to access protected plugin channel APIs without proper authentication.

Impact

Exploitation of this vulnerability allows unauthorized access to plugin channel APIs that are supposed to require gateway authentication.

Remediation

Users can upgrade to OpenClaw version 2026.2.26 or later to address this vulnerability.

Added: Mar 19, 2026, 10:33 PM
Updated: Mar 19, 2026, 10:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
4.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.