CVE-2026-32004: OpenClaw < 2026.3.2 - Authentication Bypass via Encoded Path in /api/channels Route
OpenClaw versions prior to 2026.3.2 contain an authentication bypass vulnerability in the /api/channels route classification due to canonicalization depth mismatch between auth-path classification and route-path canonicalization. Attackers can bypass plugin route authentication checks by submitting deeply encoded slash variants such as multi-encoded %2f to access protected /api/channels endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.3.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32004?
CVE-2026-32004 is classified as a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2026-32004?
To mitigate CVE-2026-32004, upgrade OpenClaw to version 2026.3.2 or later.
What components are affected by CVE-2026-32004?
CVE-2026-32004 affects all OpenClaw versions prior to 2026.3.2.
What type of vulnerability is CVE-2026-32004?
CVE-2026-32004 is an authentication bypass vulnerability.
Where does CVE-2026-32004 occur within the application?
CVE-2026-32004 occurs in the /api/channels route of OpenClaw.