
Gateway plugin auth bypass (CVE-2026-32036) in `OpenClaw` allows unauthorized access to `/api/channels` via dot-segment traversal. #AuthBypass #PathTraversal #OpenClaw https://www.pulsepatch.io/posts/cve-2026-32036-openclaw-gateway-auth-bypass
Post summary
CVE-2026-32036 is a path‑traversal authentication bypass in the OpenClaw gateway plugin that allows attackers to access /api/channels through dot‑segment traversal.

