CVE-2026-28395Disclosure(openclaw / openclaw)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as loopback addresses, allowing the relay HTTP/WS server to bind to all interfaces when a wildcard cdpUrl is configured. Remote attackers can access relay HTTP endpoints off-host to leak service presence and port information, or conduct denial-of-service and brute-force attacks against the relay token header.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1327

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-07: 1Mentions · 2026-03-10: 1Patch / Workaround · 2026-03-05: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-07: 1Technical Details · 2026-03-10: 103-0503-0703-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-051
Patch1
2026-03-071
Disclosure1
2026-03-101
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 OpenClaw, Improper Network Binding, #CVE-2026-28395 (MEDIUM) https://dailycve.com/openclaw-improper-network-binding-cve-2026-28395-medium/

    Post summary

    The tweet announces CVE‑2026‑28395 as an improper network binding flaw with medium severity, but provides no proof‑of‑concept, exploit details, or patch information.

    0000048
    167 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28395 OpenClaw version 2026.1.14-1 prior to 2026.2.12 contain an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server… https://www.cve.org/CVERecord?id=CVE-2026-28395

    Post summary

    The post announces CVE-2026-28395, noting that OpenClaw versions before 2026.2.12 suffer from improper network binding in the Chrome extension relay server.

    00000170
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28395: CRITICAL] OpenClaw version 2026.1.14-1 has a critical network binding vulnerability allowing remote attackers to access HTTP endpoints and exploit services. Update to version 2026.2.12 to st...#cve,CVE-2026-28395,#cybersecurity https://cvefind.com/CVE-2026-28395

    Post summary

    The message announces a critical vulnerability (CVE‑2026‑28395) in OpenClaw and recommends upgrading to version 2026.2.12 to remediate it.

    0000065
    596 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more