OpenClaw Authentication Bypass Vulnerability in Control UI Bootstrap Config Endpoint

Vulnerability

An authentication bypass vulnerability has been identified in OpenClaw versions prior to 2026.4.22. This vulnerability exists in the Control UI bootstrap config endpoint, allowing unauthenticated attackers to access sensitive configuration fields. The bootstrap config route can be accessed without a valid Gateway token, exposing confidential bootstrap and configuration information that is meant for authenticated Control UI sessions.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive configuration information, which could be misused to manipulate or disrupt the application's functionality.

Reproduction

To reproduce this vulnerability, send a GET request to the Control UI bootstrap config endpoint without including a Gateway token. This can be done by accessing the endpoint directly or by using a tool that allows for the omission of authentication headers. The response will include sensitive configuration information that should only be available to authenticated users.

Remediation

Users can update to OpenClaw version 2026.4.22 or later, where this vulnerability has been fixed.

Added: May 11, 2026, 7:11 PM
Updated: May 11, 2026, 7:11 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.7
remediation
0.0
relevance
8.0
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.