CVE-2026-3690CWE-291

OpenClaw Canvas Authentication Bypass Vulnerability

High · published April 11, 2026

CVSS v3.0
7.4
EPSS
1%
Percentile
49.7
In the wild
Unconfirmed
What it is

OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of OpenClaw. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the implementation of the the authentication function for canvas endpoints. The issue results from improper implementation of authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-29311.

The record
Technical detail
CVSS v3.0
7.4 · HIGH
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00671 · 49.7th percentile
Weakness
CWE-291 · Reliance on IP Address for Authentication
Published
2026-04-11T00:17Z
EPSS history
Timeline
  • 11 APR 00:17Z
    OpenClaw Canvas Authentication Bypass Vulnerability
    cvelistv5