CVE-2026-26322Disclosure(openclaw / openclaw)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient restrictions, which could cause the OpenClaw host to attempt outbound WebSocket connections to user-specified targets. This requires the ability to invoke tools that accept `gatewayUrl` overrides (directly or indirectly). In typical setups this is limited to authenticated operators, trusted automation, or environments where tool calls are exposed to non-operators. In other words, this is not a drive-by issue for arbitrary internet users unless a deployment explicitly allows untrusted users to trigger these tool calls. Some tool call paths allowed `gatewayUrl` overrides to flow into the Gateway WebSocket client without validation or allowlisting. This meant the host could be instructed to attempt connections to non-gateway endpoints (for example, localhost services, private network addresses, or cloud metadata IPs). In the common case, this results in an outbound connection attempt from the OpenClaw host (and corresponding errors/timeouts). In environments where the tool caller can observe the results, this can also be used for limited network reachability probing. If the target speaks WebSocket and is reachable, further interaction may be possible. Starting in version 2026.2.14, tool-supplied `gatewayUrl` overrides are restricted to loopback (on the configured gateway port) or the configured `gateway.remote.url`. Disallowed protocols, credentials, query/hash, and non-root paths are rejected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-20); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-20: 3Mentions · 2026-03-22: 1Patch / Workaround · 2026-02-20: 2Technical Details · 2026-02-20: 3Technical Details · 2026-03-22: 102-2003-22
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-203
Disclosure2Patch1
2026-03-221
General1
Full discourse4 posts
  • Sattyam Jain@Sattyamjjain
    General

    The CVEs: - CVE-2026-25253: One-click RCE (CVSS 8.8) - CVE-2026-26322: SSRF in Gateway - CVE-2026-26329: Path traversal in uploads - Default bind to 0.0.0.0:18789 Any website could hijack a dev's agent. Zero interaction.

    Post summary

    The note lists three new CVEs with brief severity and attack surface details, highlights a default open port, and warns that any site could hijack a developer’s agent with zero interaction.

    1000031
    58 followersView on X
  • Bob Vasic@bobdrox
    Disclosure

    A critical Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-26322) has been discovered in OpenClaw, a personal AI assistant, potentially allowing attackers to access internal resources. #cybersecurity #cybersecurity

    Post summary

    A critical SSRF vulnerability (CVE‑2026‑26322) was discovered in OpenClaw, enabling attackers to potentially access internal resources.

    1000048
    1.4K followersView on X
  • Jeff DeJaegher@DejaegherJeff
    Patch

    I was going to start diving into OpenClaw, but this is scary: Recent activity: Six vulnerabilities patched Feb 18–20, including: CVE-2026-26322: SSRF in Gateway tool (high, CVSS 7.6) – attacker can force unauthorized WebSocket requests. CVE-2026-26329: Path traversal in browser upload – read arbitrary host files via crafted paths. CVE-2026-26326: Info disclosure – secrets (API keys/tokens) leaked via skills.status endpoint to read clients. These are fixes for recently discovered flaws; OpenClaw users are urged to update to 2026.2.14+.

    Post summary

    The post lists three recent CVEs affecting OpenClaw, explains their impacts (SSRF, path traversal, info disclosure), and urges users to apply the 2026.2.14+ patch.

    0000054
    915 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26322 OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient restrictions, whic… https://www.cve.org/CVERecord?id=CVE-2026-26322

    Post summary

    The text announces a new vulnerability (CVE‑2026‑26322) affecting OpenClaw’s Gateway tool, explains the flaw, and indicates that a newer version likely contains a fix.

    00000119
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more