OpenClaw Authentication Bypass Vulnerability in Remote Onboarding Component Allowing Credential Exfiltration

Vulnerability

An authentication bypass vulnerability has been identified in OpenClaw versions prior to 2026.3.28. This vulnerability exists in the remote onboarding component, which accepts discovery endpoints without explicit trust confirmation. As a result, unauthenticated endpoints can be exploited to redirect onboarding processes toward malicious gateways, potentially allowing attackers to capture gateway credentials or intercept traffic.

Impact

Exploitation of this vulnerability could lead to unauthorized access to gateway credentials or interception of gateway traffic, allowing attackers to manipulate or misuse this information.

Remediation

Users can upgrade to OpenClaw version 2026.3.28 or later to address this vulnerability.

Added: Apr 23, 2026, 10:36 PM
Updated: Apr 23, 2026, 10:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.4
remediation
0.0
relevance
6.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.