OpenClaw Authentication Bypass Vulnerability in Remote Onboarding Component Allowing Credential Exfiltration
Vulnerability
An authentication bypass vulnerability has been identified in OpenClaw versions prior to 2026.3.28. This vulnerability exists in the remote onboarding component, which accepts discovery endpoints without explicit trust confirmation. As a result, unauthenticated endpoints can be exploited to redirect onboarding processes toward malicious gateways, potentially allowing attackers to capture gateway credentials or intercept traffic.
Impact
Exploitation of this vulnerability could lead to unauthorized access to gateway credentials or interception of gateway traffic, allowing attackers to manipulate or misuse this information.
Remediation
Users can upgrade to OpenClaw version 2026.3.28 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
