CVE-2026-3690
NONE EPSS 47.4%
Published Apr 11, 20262mo ago · Modified Jun 17, 20261w ago
Published Apr 11, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago
Description
OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of OpenClaw. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the the authentication function for canvas endpoints. The issue results from improper implementation of authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-29311.
Threat Intelligence
EPSS Exploit Probability
47.4% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available
Weaknesses 1
CWE-291
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| openclaw | openclaw | * | <2026.2.19 |
References 2
- github.com https://github.com/openclaw/openclaw/security/advisories/GHSA-vvjh-f6p9-5vcf
- zerodayinitiative.com https://www.zerodayinitiative.com/advisories/ZDI-26-228/
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.