CVE-2026-42421

OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attackers can maintain unauthorized access to WebSocket connections after token rotation by exploiting the failure to disconnect existing shared-token sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

30 Apr 2026, 14:04

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw openclaw
Openclaw
References () https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5 - () https://github.com/openclaw/openclaw/commit/d7c3210cd6f5fdfdc1beff4c9541673e814354d5 - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-5h3f-885m-v22w - () https://github.com/openclaw/openclaw/security/advisories/GHSA-5h3f-885m-v22w - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-websocket-session-persistence-via-shared-gateway-token-rotation - () https://www.vulncheck.com/advisories/openclaw-websocket-session-persistence-via-shared-gateway-token-rotation - Third Party Advisory

28 Apr 2026, 19:37

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 19:37

Updated : 2026-04-30 14:04


NVD link : CVE-2026-42421

Mitre link : CVE-2026-42421

CVE.ORG link : CVE-2026-42421


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-613

Insufficient Session Expiration