CVE-2026-28458 - Vulnerability Analysis
HighCVSS: 8.1Last Updated: March 6, 2026
OpenClaw - Authentication Bypass
Published: March 5, 2026Updated: March 6, 2026Remote Exploitable
Overview
OpenClaw < 2026.2.1 contains a broken authentication vulnerability in the Browser Relay /cdp WebSocket endpoint that does not require authentication tokens, letting attackers steal session cookies and execute JavaScript in other tabs, exploit requires the extension to be installed and enabled.
Severity & Score
Severity: High
CVSS Score: 8.1
Impact
Attackers can steal session cookies and execute JavaScript in other browser tabs, leading to session hijacking and potential account compromise.
Mitigation
Update to version 2026.2.1 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-28458
- Severity
- High
- CVSS Score
- 8.1
- Type
- broken_authentication
- Status
- new
CWE
- CWE-306
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N