LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32045

openclaw · openclaw

Published
CVSS5.9
Severitymedium
WeaknessCWE-290
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networks can exploit this misconfiguration to access HTTP gateway routes without proper authentication credentials.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32045

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32045.