Incorrect authorization in OpenClaw - CVE-2026-32001
Published: May 1, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote user to inject unauthorized node events.
The vulnerability exists due to incorrect authorization in the WebSocket connect path when handling role=node connections authenticated with a shared gateway token without device identity or pairing. A remote user can connect as role=node and call node.event to inject unauthorized node events.
This can trigger agent.request and voice.transcript flows without node device pairing.