CVE-2026-32001 is an authentication bypass vulnerability in OpenClaw versions prior to 2026.2.22, allowing clients with a shared gateway token to connect as a 'node' without device identity verification. Rated Medium severity (CVSS 5.4), this flaw allows attackers with low privileges and network access to inject unauthorized node.event calls during WebSocket handshake, potentially triggering sensitive agent.request and voice.transcript flows with low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or community discussion, indicating a low current threat landscape for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.22CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.22CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.