
🟠 CVE-2026-34503 - High OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access thr... https://www.thehackerwire.com/vulnerability/CVE-2026-34503/ https://t.co/rIKuWAwpK0
Post summary
The message reports a high‑severity vulnerability in OpenClaw where WebSocket sessions are not terminated after device removal or token revocation, enabling attackers with revoked credentials to retain unauthorized access; no PoC, exploit, or patch information is included.

