#VU125103 Missing Authentication for Critical Function in OpenClaw - CVE-2026-32041
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to access browser-control routes without authentication.
The vulnerability exists due to missing authentication for critical function in browser-control routes when browser control starts without explicit auth credentials and automatic auth bootstrap fails. A local user can access exposed browser-control routes to access browser-control routes without authentication.
A loopback-reachable SSRF path may also reach the exposed routes.