Missing Authentication for Critical Function in OpenClaw - CVE-2026-28485
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to access sensitive in-session data and perform privileged browser actions.
The vulnerability exists due to improper access control in the local browser-control HTTP route /agent/act and related browser-control handlers when handling local browser-control HTTP requests without configured authentication. A remote attacker can send a specially crafted request to access sensitive in-session data and perform privileged browser actions.
Exposure is primarily related to loopback-bound local-process and local-proxy boundaries in configurations where authentication is not configured.