CVE-2026-28472: OpenClaw < 2026.2.2 - Device Identity Check Bypass in Gateway WebSocket Connect Handshake
OpenClaw versions prior to 2026.2.2 contain a vulnerability in the gateway WebSocket connect handshake in which it allows skipping device identity checks when auth.token is present but not validated. Attackers can connect to the gateway without providing device identity or pairing by exploiting the presence check instead of validation, potentially gaining operator access in vulnerable deployments.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28472?
The severity of CVE-2026-28472 is classified as critical due to the potential for unauthorized access to sensitive systems.
How do I fix CVE-2026-28472?
To fix CVE-2026-28472, upgrade OpenClaw to version 2026.2.2 or later to ensure proper device identity checks are enforced.
What systems are affected by CVE-2026-28472?
CVE-2026-28472 affects all versions of OpenClaw prior to version 2026.2.2.
What type of vulnerability is CVE-2026-28472?
CVE-2026-28472 is a device identity check bypass vulnerability during the WebSocket connect handshake.
Who is the vendor responsible for CVE-2026-28472?
OpenClaw is the vendor responsible for the software affected by CVE-2026-28472.