Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32045

27
FAUCET Score

CVE-2026-32045 is a critical authentication bypass vulnerability affecting OpenClaw versions prior to 2026.2.21, where tokenless Tailscale header authentication is incorrectly applied to HTTP gateway routes. This misconfiguration allows attackers on trusted networks to bypass token and password requirements, gaining unauthorized access to these routes. Rated 9.1 CRITICAL on the CVSS scale, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction or privileges required, potentially leading to high confidentiality and integrity impacts. There is currently no evidence of active exploitation, nor publicly available exploit code, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 2026.2.21CPE match
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
< 2026.2.21CPE matchmatch criteria
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 10th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: openclawFixed in: 2026.2.21

Vendor Advisories (1)

npmGHSA-hff7-ccv5-52f8medium

OpenClaw's gateway tokenless Tailscale auth applied to HTTP routes

Mar 3, 2026

References

github.com / openclaw/openclaw/commit/356d61aacfa5b0f1d5830716ec59d70682a3e7b8
Patch
github.com / openclaw/openclaw/security/advisories/GHSA-hff7-ccv5-52f8
MitigationVendor Advisory
vulncheck.com / advisories/openclaw-authentication-bypass-in-http-gateway-routes-via-tokenless-tailscale-auth
Third Party Advisory