Vulnerability Description
OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote credentials in local mode. Attackers can exploit misconfigured local auth references to cause CLI and helper paths to select incorrect credential sources, potentially bypassing intended local authentication boundaries.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openclaw | Openclaw | < 2026.3.11 |
Related Weaknesses (CWE)
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-qvr7-g57c-mrc7Vendor Advisory
- https://www.vulncheck.com/advisories/openclaw-credential-fallback-logic-bypass-vThird Party Advisory
FAQ
What is CVE-2026-32970?
CVE-2026-32970 is a vulnerability with a CVSS score of 2.5 (LOW). OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and gateway.auth.password SecretRefs are treated as unset, allowing fallback to remote...
How severe is CVE-2026-32970?
CVE-2026-32970 has been rated LOW with a CVSS base score of 2.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-32970?
Check the references section above for vendor advisories and patch information. Affected products include: Openclaw Openclaw.