← Back to CVE search

CVE-2026-41356

OpenClaw

Description

OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentials can maintain unauthorized access through existing WebSocket connections after token rotation.

CVSS 5.4EPSS 0.186%Risk 0.55
View source
Published
2026-04-23 22:16:43
Affected versions
<2026.3.31
Type
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N