CVE-2026-28395: OpenClaw 2026.1.14-1 < 2026.2.12 - Unintended Public Binding of Chrome Extension Relay via Wildcard cdpUrl

Published Mar 5, 2026
·
Updated

OpenClaw version 2026.1.14-1 prior to 2026.2.12 contains an improper network binding vulnerability in the Chrome extension (must be installed and enabled) relay server that treats wildcard hosts as loopback addresses, allowing the relay HTTP/WS server to bind to all interfaces when a wildcard cdpUrl is configured. Remote attackers can access relay HTTP endpoints off-host to leak service presence and port information, or conduct denial-of-service and brute-force attacks against the relay token header.

Affected Software

2 affected components
OpenClaw OpenClaw<2026.2.12
OpenClaw Openclaw Node.js>=2026.1.14-1<2026.2.12

Event History

Mar 5, 2026
CVE Published
via MITRE·09:59 PM
Data Sourced
via MITRE·09:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 14, 58369
Event
via NVD·06:51 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-28395?

CVE-2026-28395 is classified as a moderate severity vulnerability due to potential unauthorized access via unintended public bindings.

2

How do I fix CVE-2026-28395?

To mitigate CVE-2026-28395, upgrade OpenClaw to version 2026.2.12 or later.

3

What is the impact of CVE-2026-28395?

The impact of CVE-2026-28395 includes possible unauthorized access to sensitive features exposed by the Chrome extension relay.

4

Which versions of OpenClaw are affected by CVE-2026-28395?

CVE-2026-28395 affects OpenClaw versions from 2026.1.14-1 up to, but not including, 2026.2.12.

5

Is the Chrome extension for OpenClaw required to exploit CVE-2026-28395?

Yes, the Chrome extension must be installed and enabled for CVE-2026-28395 to be exploitable.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203