Authentication Bypass Vulnerability in OpenClaw Canvas Gateway
CVE-2026-35634

5.1MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-35634?

A vulnerability in OpenClaw prior to version 2026.3.23 permits authentication bypass within the Canvas gateway. The function authorizeCanvasRequest() fails to validate bearer tokens or canvas capabilities, enabling attackers to execute unauthenticated loopback HTTP and WebSocket requests. This oversight can lead to unauthorized access to sensitive Canvas routes, posing a significant security risk for users.

Affected Version(s)

OpenClaw 0 < 2026.3.23

OpenClaw 2026.3.23

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

smaeljaish771
.