Authentication Bypass Vulnerability in OpenClaw by OpenClaw
CVE-2026-35656
6.3MEDIUM
What is CVE-2026-35656?
An authentication bypass vulnerability exists in OpenClaw prior to version 2026.3.22 due to improper processing of the X-Forwarded-For header when the trustedProxies configuration is in use. This flaw allows remote attackers to spoof loopback hops by injecting forged forwarding headers. Consequently, attackers can bypass canvas authentication mechanisms and evade rate-limiting protections, effectively masquerading as legitimate loopback clients. It is critical for users and administrators to upgrade to the patched version to mitigate these security risks.
Affected Version(s)
OpenClaw 0 < 2026.3.22
OpenClaw 2026.3.22
