CVE-2026-28485Disclosure(openclaw / openclaw)

LOWCVSS 7.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged operations. Remote attackers on the local network or local processes can execute arbitrary browser-context actions and access sensitive in-session data by sending requests to unauthenticated endpoints.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-06: 4Technical Details · 2026-03-06: 303-06
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28485 OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local calle… https://www.cve.org/CVERecord?id=CVE-2026-28485 ----- Traducción: CVE-2026-28485 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑28485, describing an authentication bypass in OpenClaw’s browser‑control route, but does not provide a PoC, exploit, or mitigation.

    0001042
    56 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28485 - High OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged o... https://www.thehackerwire.com/vulnerability/CVE-2026-28485/ https://t.co/eth9EO6Mtc

    Post summary

    The post discloses a high‑severity authentication bypass in OpenClaw versions, detailing how local callers can misuse the /agent/act route, without providing PoC, exploit, or patch information.

    0001062
    125 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-28485 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-28485-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-28485 #openclaw #

    Post summary

    The post announces a CVE alert for CVE-2026-28485 in OpenClaw, with no additional technical, PoC, exploit, or patch details provided.

    00010143
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28485 OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local calle… https://www.cve.org/CVERecord?id=CVE-2026-28485

    Post summary

    The text reports a weakness in OpenClaw that permits unauthorized local browser-control calls due to missing authentication on the /agent/act route. No exploitation, patch, or workaround information is mentioned.

    00000274
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more