Authentication Bypass Vulnerability in OpenClaw Canvas Gateway
CVE-2026-35634
5.1MEDIUM
What is CVE-2026-35634?
A vulnerability in OpenClaw prior to version 2026.3.23 permits authentication bypass within the Canvas gateway. The function authorizeCanvasRequest() fails to validate bearer tokens or canvas capabilities, enabling attackers to execute unauthenticated loopback HTTP and WebSocket requests. This oversight can lead to unauthorized access to sensitive Canvas routes, posing a significant security risk for users.
Affected Version(s)
OpenClaw 0 < 2026.3.23
OpenClaw 2026.3.23
