CVE-2026-41333
LOW3.7CVSS v3
—CVSS v2
0.08%
EPSS (exploit probability)
CWE-799CWE
Description
OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute force attacks against weak shared passwords.
CVSS v3 vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected routers (0)
No routers currently mapped to this CVE in our database.