CVE-2026-28468: Openclaw
High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.
OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests without requiring gateway authentication, allowing local attackers to access browser control endpoints. A local attacker can enumerate tabs, retrieve WebSocket URLs, execute JavaScript, and exfiltrate cookies and session data from authenticated browser contexts.
Affected products
- Openclaw Openclaw: from 2026.1.29, before 2026.2.14 (fixed in 2026.2.14)
Published 2026-03-05. Last modified 2026-06-17.