Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-43585: OpenClaw before 2026.4.15 allows revoked tokens to be reused

CVE-2026-43585
Summary

A security issue in OpenClaw before 2026.4.15 can allow attackers to use old, revoked tokens to access the system. This is because the system does not correctly check the token's validity each time it is used. To protect your system, you should update to OpenClaw 2026.4.15 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
openclaw openclaw < 2026.4.15
cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Original title
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-re...
Original description
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized gateway access.
nvd CVSS3.1 9.8
nvd CVSS4.0 9.2
Vulnerability type
CWE-672
Published: 6 May 2026 · Updated: 1 Jun 2026 · First seen: 7 May 2026