#VU125119 Authentication bypass using an alternate path or channel in OpenClaw - CVE-2026-32004
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to bypass authentication controls.
The vulnerability exists due to authentication bypass using an alternate path or channel in plugin /api/channels route classification when handling deeply encoded alternate-path requests. A remote user can send a specially crafted encoded request to bypass authentication controls.
Exploitation requires deployments that expose plugin HTTP routes and rely on gateway authentication for /api/channels/* protection.