Back

HIGH

OpenClaw < 2026.3.1 - Unauthenticated Browser Control Access via Failed Auth Bootstrap

Published Mar 19, 2026

Description

OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can exploit this to access browser-control routes including evaluate-capable actions without valid credentials.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 19, 2026
Updated Jun 23, 2026
Reserved Mar 10, 2026
CISA Vulnrichment
Updated Mar 20, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Mar 19, 2026
Updated Jun 23, 2026
Exploited since n/a
EUVD-2026-13330 GHSA-VPJ2-69HF-RPPW