CVE-2026-43569

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicious workspace plugins that are automatically selected and enabled during authentication setup without explicit user consent.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

07 May 2026, 01:52

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
First Time Openclaw
Openclaw openclaw
References () https://github.com/openclaw/openclaw/commit/2d97eae53e212ae26f3aebcd6a50ffc6877f770d - () https://github.com/openclaw/openclaw/commit/2d97eae53e212ae26f3aebcd6a50ffc6877f770d - Patch
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-939r-rj45-g2rj - () https://github.com/openclaw/openclaw/security/advisories/GHSA-939r-rj45-g2rj - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-untrusted-provider-plugin-auto-enablement-via-workspace-provider-auth - () https://www.vulncheck.com/advisories/openclaw-untrusted-provider-plugin-auto-enablement-via-workspace-provider-auth - Third Party Advisory

05 May 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-05 12:16

Updated : 2026-05-07 01:52


NVD link : CVE-2026-43569

Mitre link : CVE-2026-43569

CVE.ORG link : CVE-2026-43569


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere