CVE-2026-41333
OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute force attacks against weak shared passwords.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-799
- Published
- 2026-04-23
- Last modified
- 2026-04-24
Affected products
- OpenClaw OpenClaw
- OpenClaw OpenClaw
Weakness type
Related vulnerabilities
- CVE-2026-85586 — phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter
- CVE-2026-54738 — Lemmy: Rate limit bypass via X-Forwarded-For header spoofing in actix-web ConnectionInfo
- CVE-2026-75773 — karakeep-app karakeep Login Endpoint auth.ts authorize excessive authentication
- CVE-2026-19898 — VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessive authentication
- CVE-2026-19897 — mangroup dtale Login Endpoint auth.py login excessive authentication
- CVE-2026-19895 — opensourcepos Open Source Point of Sale Login Endpoint Filters.php index excessive authentication
- CVE-2024-23565 — HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail...
- CVE-2026-33434 — Wazuh: Rate Limit Bypass via /events Endpoint