Ad

CVE-2026-28485

HIGH CVSS 4.0: 7.5 EPSS 0.12%
Updated Mar 05, 2026
OpenClaw
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions before 2026.2.12
Type CWE-306 (Missing Authentication for Critical Function)
Vendor OpenClaw
Public PoC No

OpenClaw versions 2026.1.5 prior to 2026.2.12 fail to enforce mandatory authentication on the /agent/act browser-control HTTP route, allowing unauthorized local callers to invoke privileged operations. Remote attackers on the local network or local processes can execute arbitrary browser-context actions and access sensitive in-session data by sending requests to unauthenticated endpoints.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v4.0