CVE-2026-3690
OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of OpenClaw. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the the authentication function for canvas endpoints. The issue results from improper implementation of authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-29311.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.67%
- CWE
- CWE-291
- Published
- 2026-04-11
- Last modified
- 2026-04-14
Affected products
- OpenClaw OpenClaw
Weakness type
Related vulnerabilities
- CVE-2026-86485 — In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket...
- CVE-2026-4252 — Tenda AC8 IPv6 check_is_ipv6 ip address for authentication
- CVE-2025-66602 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation....
- CVE-2025-59101 — Insufficient Session Management in dormakaba access manager
- CVE-2025-34202 — Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
- CVE-2024-23309 — The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in...
- CVE-2024-32765 — QTS, QuTS hero
- CVE-2023-7211 — Uniway Router Administrative Web Interface reliance on ip address for authentication