CVE-2026-34503: OpenClaw < 2026.3.28 - Incomplete WebSocket Session Termination on Device Removal and Token Revocation

Published Mar 31, 2026
·
Updated

Summary

Removing a device or revoking its token updated stored credentials but did not disconnect already-authenticated WebSocket sessions.

Impact

A revoked device could continue using its existing live session until reconnect, extending access beyond credential removal.

Affected Component

src/gateway/server-methods/devices.ts, src/gateway/server.impl.ts

Fixed Versions

- Affected: <= 2026.3.24 - Patched: >= 2026.3.28 - Latest stable 2026.3.28 contains the fix.

Fix

Fixed by commit 7a801cc451 (Gateway: disconnect revoked device sessions).

Other sources

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection.

MITRE

Affected Software

3 affected componentsFixes available
OpenClaw OpenClaw<2026.3.28
npm/openclaw<=2026.3.24
2026.3.28
OpenClaw Openclaw Node.js<2026.3.28

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/openclaw to a version that resolves this vulnerability.

    Fixed in 2026.3.28
  2. Upgrade

    Upgrade OpenClaw to a version that resolves this vulnerability.

    Fixed in 2026.3.28Patch 7a801cc451
  3. Compensating control

    If upgrading is not immediately possible, revoke/terminate existing WebSocket sessions for removed devices/revoked tokens by forcing client reconnection (the issue allows continued access until reconnect).

Event History

Mar 31, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·11:52 PM
Data Sourced
via GitHub·11:52 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-34503?

CVE-2026-34503 is categorized as a high severity vulnerability due to the risk of unauthorized access through active WebSocket sessions.

2

How do I fix CVE-2026-34503?

To fix CVE-2026-34503, upgrade OpenClaw to version 2026.3.28 or later, which addresses the incomplete WebSocket session termination.

3

What vulnerabilities are associated with CVE-2026-34503?

CVE-2026-34503 specifically relates to the failure of OpenClaw to disconnect WebSocket sessions upon device removal or token revocation.

4

Who is affected by CVE-2026-34503?

Users of OpenClaw versions prior to 2026.3.28 are at risk due to the incomplete session termination vulnerability.

5

What type of attack can exploit CVE-2026-34503?

CVE-2026-34503 can be exploited by attackers who have revoked credentials but can still maintain access via active WebSocket sessions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203