CVE-2026-32014 is a high-severity metadata spoofing vulnerability affecting OpenClaw versions prior to 2026.2.26, where reconnect platform and deviceFamily fields are accepted without proper signature binding. This flaw allows an attacker with low privileges on an adjacent network to bypass platform-based node command policies and gain unauthorized access to restricted commands. Rated with a CVSS score of 8.0, it poses a high risk to confidentiality, integrity, and availability. Currently, there is no public exploit code available, no evidence of active exploitation, and it is not listed in CISA's KEV catalog, with a very low EPSS score indicating a low probability of exploitation in the wild. Community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.26CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.26CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.