Reliance on Untrusted Inputs in a Security Decision in OpenClaw - CVE-2026-32057
Published: May 1, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote user to bypass an authorization boundary.
The vulnerability exists due to reliance on untrusted inputs in a security decision in the trusted-proxy Control UI pairing logic when handling websocket connections with a user-controlled client.id value. A remote user can supply client.id=control-ui to bypass an authorization boundary.
Exploitation requires trusted-proxy authentication to be enabled, and an authenticated session with the node role can connect unpaired and reach node event methods.