CVE-2026-41333

OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute force attacks against weak shared passwords.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

28 Apr 2026, 18:55

Type Values Removed Values Added
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/commit/af0c0862f22ca4492406a3103d05e3628f94cbe9 - () https://github.com/openclaw/openclaw/commit/af0c0862f22ca4492406a3103d05e3628f94cbe9 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-6p8r-6m93-557f - () https://github.com/openclaw/openclaw/security/advisories/GHSA-6p8r-6m93-557f - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-authentication-rate-limiting-bypass-via-fake-devicetoken - () https://www.vulncheck.com/advisories/openclaw-authentication-rate-limiting-bypass-via-fake-devicetoken - Third Party Advisory
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

23 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 22:16

Updated : 2026-04-28 18:55


NVD link : CVE-2026-41333

Mitre link : CVE-2026-41333

CVE.ORG link : CVE-2026-41333


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-799

Improper Control of Interaction Frequency