CVE-2026-32045 is a critical authentication bypass vulnerability affecting OpenClaw versions prior to 2026.2.21, where tokenless Tailscale header authentication is incorrectly applied to HTTP gateway routes. This misconfiguration allows attackers on trusted networks to bypass token and password requirements, gaining unauthorized access to these routes. Rated 9.1 CRITICAL on the CVSS scale, this vulnerability is easily exploitable over the network with low attack complexity and no user interaction or privileges required, potentially leading to high confidentiality and integrity impacts. There is currently no evidence of active exploitation, nor publicly available exploit code, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2026.2.21CPE match | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | ||
< 2026.2.21CPE matchmatch criteria | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.