CVE-2026-43585: Openclaw
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized gateway access.
Affected products
- Openclaw Openclaw: before 2026.4.15 (fixed in 2026.4.15)
Published 2026-05-06. Last modified 2026-06-17.