CVE-2026-3690

NONE EPSS 47.4%
Published Apr 11, 20262mo ago · Modified Jun 17, 20261w ago
Find Similar
Published Apr 11, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago

Description

OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of OpenClaw. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the the authentication function for canvas endpoints. The issue results from improper implementation of authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-29311.

Threat Intelligence

EPSS Exploit Probability
47.4% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available

Weaknesses 1

CWE-291

Affected Products 1

VendorProductVersionRange
openclawopenclaw* <2026.2.19

References 2

  • github.com https://github.com/openclaw/openclaw/security/advisories/GHSA-vvjh-f6p9-5vcf
    ExploitThird Party Advisory
  • zerodayinitiative.com https://www.zerodayinitiative.com/advisories/ZDI-26-228/
    ExploitThird Party Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.