CVE-2026-32034 is an authentication bypass vulnerability affecting OpenClaw versions prior to 2026.2.21, specifically within its Control UI. This allows an attacker with leaked or intercepted credentials to gain high-privilege Control UI access when the `allowInsecureAuth` setting is enabled and the gateway is exposed over plaintext HTTP, bypassing device identity and pairing verification. Rated 8.1 High (CVSSv3.1), it has a low attack complexity and requires low privileges (stolen credentials) to achieve high integrity and availability impacts over a network. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.21CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.21CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.