OpenClaw Canvas Authentication Bypass Vulnerability in OpenClaw
CVE-2026-3690

7.4HIGH

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
11 April 2026

What is CVE-2026-3690?

The OpenClaw Canvas Authentication Bypass vulnerability allows remote attackers to exploit a flaw in the authentication function for canvas endpoints. Improper implementation of authentication enables unauthorized access, allowing attackers to bypass security measures entirely. Given that authentication is not required for exploitation, affected installations of OpenClaw are at significant risk. Administrators should promptly assess their systems and implement necessary mitigations to safeguard against potential intrusions. For more detailed guidance, refer to vendor advisory resources.

Affected Version(s)

OpenClaw 2026.2.17

References

CVSS V3.0

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.