CVE-2026-28485: OpenClaw 2026.1.5 < 2026.2.12 - Missing Authentication in Browser Control HTTP Endpoints
OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged operations. Remote attackers on the local network or local processes can execute arbitrary browser-context actions and access sensitive in-session data by sending requests to unauthenticated endpoints.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28485?
The severity of CVE-2026-28485 is classified as high due to the potential for unauthorized access to privileged operations.
How do I fix CVE-2026-28485?
To fix CVE-2026-28485, upgrade OpenClaw to version 2026.2.12 or later, which implements mandatory authentication.
Who is affected by CVE-2026-28485?
CVE-2026-28485 affects OpenClaw versions from 2026.1.5 up to, but not including, 2026.2.12.
What operations can be invoked without authentication in CVE-2026-28485?
Unauthorized local callers can invoke privileged operations through the /agent/act browser-control HTTP route due to the lack of authentication.
Can CVE-2026-28485 be exploited remotely?
CVE-2026-28485 is not exploitable remotely as it requires unauthorized local access to invoke the vulnerable HTTP endpoint.