SB2026022736 - Remote code execution in OpenClaw



SB2026022736 - Remote code execution in OpenClaw

Published: February 27, 2026

Security Bulletin ID SB2026022736
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2026-25253)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to the Control UI obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection to the URL without prompting the user. A remote attacker can trick the victim into visiting a specially crafted website and obtain a security token that can be used later to manipulate the application via the established WebSocket connection.

Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.


Remediation

Install update from vendor's website.