#VU125077 Authentication Bypass by Spoofing in OpenClaw - CVE-2026-32014
Published: April 7, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to gain access to commands that should remain blocked for the originally paired platform.
The vulnerability exists due to authentication bypass by spoofing in the node reconnect metadata handling when accepting client-supplied platform and deviceFamily metadata during node reconnection. A remote user can spoof reconnect metadata to gain access to commands that should remain blocked for the originally paired platform.
Exploitation requires an already paired node identity on the trusted network, and affects configurations where node command policy differs by platform.