Insufficient Session Expiration in OpenClaw - #VU125247

 

Insufficient Session Expiration in OpenClaw - #VU125247

Published: April 8, 2026


Vulnerability identifier: #VU125247
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to maintain access to an active WebSocket session after credential rotation.

The vulnerability exists due to improper session expiration in the WebSocket session handling for the gateway device.token.rotate operation when rotating device credentials. A remote user can continue using an already-authenticated WebSocket session to maintain access to an active WebSocket session after credential rotation.

This is a post-compromise revocation gap affecting already-authenticated sessions.


Affected software

OpenClaw

Remediation

Install security update from vendor's website.

OpenClaw - update to 2026.3.31

External References

Related Security Bulletins