CVE-2026-43569Disclosure(openclaw / openclaw)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicious workspace plugins that are automatically selected and enabled during authentication setup without explicit user consent.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-05); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-06-11: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 1Technical Details · 2026-06-11: 105-0505-0606-11
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-061
Patch1
2026-06-111
Disclosure1
Full discourse4 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    🚨 7 ثغرات خطيرة في OpenClaw! ⚠️ الثغرتين الأخطر ممكن تستغل بدون صلاحيات (Unauthenticated): (CVE-2026-43534) | تقييم 9.3 تخلي بيانات خارجية (External hook metadata) تعامل كأنها أوامر داخلية موثوقة للنظام و ثد تنتقل إلى سياق أعلى ثقة داخل الـ agent بدون تدخل من المستخدم. (CVE-2026-43566) | تقييم 9.1 المخترق يرسل (Webhook) من مصدر غير موثوق، ويتجاوز نظام الصلاحيات ليتنفذ الأمر كأنه من مالك النظام نفسه! ⚙️ الخمس ثغرات الباقية تحتاج صلاحيات منخفضة للاستغلال وكلها بتقييم 8.8: (CVE-2026-43571): إضافة خبيثة تنزل مكان الإضافة الرسمية بسبب خلل في ترتيب البحث وتتجاوز أدوات التحقق. (CVE-2026-43569): إضافة غير موثوقة تتفعل تلقائياً وقت الإعداد الأولي (Onboarding) بدون إذن المستخدم. (CVE-2026-43530): استخدام أدوات مجمعة مثل (busybox) يخلي المخترق يموّه الأوامر. النظام يوافق على أمر آمن ظاهرياً لكن اللي يتنفذ فعلياً أمر خبيث. (CVE-2026-42435): حقن متغيرات حساسة في الشل (مثل SHELLOPTS) على مستوى (argv) وتجاوز الفحص قبل التنفيذ. (CVE-2026-42434): هروب الوكيل من الـ Sandbox. 🛡️ حدّث فوراً لإصدار (2026.4.14).

    Post summary

    The post announces seven severe OpenClaw vulnerabilities, details their technical nature, and urges users to patch with version 2026.4.14, without providing PoCs, exploits, or active exploitation evidence.

    03016102.5K
    49.3K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    New advisory to triage: CVE-2026-43569. OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled… Inventory first. Panic never helps.

    Post summary

    An advisory announces an authentication bypass in OpenClaw 2026.4.9 and earlier, enabling untrusted workspace plugins, with no patch, exploit, or in‑the‑wild activity disclosed.

    1000080
    331 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43569 Authentication Bypass in OpenClaw Before 2026.4.9 via Malicious Workspace Plugins https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43569

    Post summary

    The post announces CVE‑2026‑43569 as an authentication bypass vulnerability in OpenClaw versions before 2026.4.9, accessed through malicious workspace plugins, with no PoC, exploit, or patch information available.

    0000055
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43569 OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding whe… https://www.cve.org/CVERecord?id=CVE-2026-43569

    Post summary

    CVE‑2026‑43569 is disclosed as an authentication bypass in OpenClaw pre‑2026.4.9 that auto‑enables untrusted plugins during non‑interactive onboarding, with no evidence of PoC, exploitation, or mitigation.

    00000132
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more