CVE-2026-32014Disclosure(openclaw / openclaw)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client without being bound into the device-auth signature. An attacker with a paired node identity on the trusted network can spoof reconnect metadata to bypass platform-based node command policies and gain access to restricted commands.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-20)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-19: 1Mentions · 2026-03-20: 2Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 103-1903-20
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-202
Disclosure1General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32014 OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client without b… https://www.cve.org/CVERecord?id=CVE-2026-32014

    Post summary

    The tweet announces that OpenClaw versions before 2026.2.26 contain a metadata spoofing flaw allowing clients to set platform and deviceFamily fields, and users should upgrade to a patched release.

    00000119
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-32014 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-32014-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32014 #openclaw #

    Post summary

    The tweet only announces the existence of CVE-2026-32014 and links to an external alert, providing no substantive details about the vulnerability or its exploitation.

    0000060
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32014 - High OpenClaw versions prior to 2026.2.26 contain a metadata spoofing vulnerability where reconnect platform and deviceFamily fields are accepted from the client without being bound into the devic... https://www.thehackerwire.com/vulnerability/CVE-2026-32014/ https://t.co/7MklG8lpe8

    Post summary

    A High‑severity metadata spoofing vulnerability (CVE‑2026‑32014) affecting OpenClaw versions prior to 2026.2.26 has been disclosed with technical details but no PoC, exploit, or patch information.

    0000044
    137 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more