CVE-2026-26327General(openclaw / openclaw)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSha256`. TXT records are unauthenticated. Prior to version 2026.2.14, some clients treated TXT values as authoritative routing/pinning inputs. iOS and macOS used TXT-provided host hints (`lanHost`/`tailnetDns`) and ports (`gatewayPort`) to build the connection URL. iOS and Android allowed the discovery-provided TLS fingerprint (`gatewayTlsSha256`) to override a previously stored TLS pin. On a shared/untrusted LAN, an attacker could advertise a rogue `_openclaw-gw._tcp` service. This could cause a client to connect to an attacker-controlled endpoint and/or accept an attacker certificate, potentially exfiltrating Gateway credentials (`auth.token` / `auth.password`) during connection. As of time of publication, the iOS and Android apps are alpha/not broadly shipped (no public App Store / Play Store release). Practical impact is primarily limited to developers/testers running those builds, plus any other shipped clients relying on discovery on a shared/untrusted LAN. Version 2026.2.14 fixes the issue. Clients now prefer the resolved service endpoint (SRV + A/AAAA) over TXT-provided routing hints. Discovery-provided fingerprints no longer override stored TLS pins. In iOS/Android, first-time TLS pins require explicit user confirmation (fingerprint shown; no silent TOFU) and discovery-based direct connects are TLS-only. In Android, hostname verification is no longer globally disabled (only bypassed when pinning).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-18: 1Mentions · 2026-02-20: 102-1802-20
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • ‘BugBounty Writeups’@bbwriteups
    General

    "The 2026 OpenClaw Vulnerability Cluster (CVE‑2026‑26323, CVE‑2026‑26327, CVE‑2026‑26317…" by gm0 #BugBounty #Cybersecurity #Hacking #InfoSec https://blog.stackademic.com/the-2026-openclaw-vulnerability-cluster-cve-2026-26323-cve-2026-26327-cve-2026-26317-188eee2cade5

    Post summary

    The tweet merely announces the presence of a cluster of CVEs in OpenClaw and links to a blog post, but it offers no additional detail about exploitation, patches, or technical specifics.

    0001050
    461 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26327 OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSh… https://www.cve.org/CVERecord?id=CVE-2026-26327

    Post summary

    The post briefly cites CVE-2026-26327 and mentions discovery beacon TXT records, but it offers no details on exploitation, patches, or false positives.

    00000102
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more