HIGH
OpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance Guard
Published Apr 20, 2026
7.1
HIGHCVSS 4.0
EPSS 0.35%
Description
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated by self-declared client metadata from WebSocket handshake rather than verified authorization state. Authenticated operator clients can spoof ACP identity labels and inject reserved provenance fields intended only for the ACP bridge by manipulating client metadata during connection.
Affected products
-
- Version 0StatusaffectedConstraints<2026.3.28
- Version 2026.3.28StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.28
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.28 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24006 Advisory
- https://github.com/advisories/GHSA-6xg4-82hv-cp6f Advisory
- https://github.com/openclaw/openclaw/commit/4b9542716c26ac77652bcaa0f562043b298b409f
- https://github.com/openclaw/openclaw/security/advisories/GHSA-6xg4-82hv-cp6f vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-client-identity-spoofing-in-chat-send-gateway-provenance-guard third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24006 | Advisory | |
| https://github.com/advisories/GHSA-6xg4-82hv-cp6f | Advisory | |
| https://github.com/openclaw/openclaw/commit/4b9542716c26ac77652bcaa0f562043b298b409f | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-6xg4-82hv-cp6f | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-client-identity-spoofing-in-chat-send-gateway-provenance-guard | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 20, 2026
Updated Apr 21, 2026
Reserved Apr 20, 2026
Link CVE-2026-41299
CISA Vulnrichment
Updated Apr 21, 2026
ENISA EUVD
EUVD-2026-24006 GHSA-6XG4-82HV-CP6F Assigner VulnCheck
Published Apr 20, 2026
Updated Apr 21, 2026
Exploited since n/a
Link EUVD-2026-24006