Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-40045

MEDIUM NVD
CVSS Score 5.7
Severity MEDIUM
Published Apr 21, 2026
Vendor unknown

Description

OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections. Attackers can forge discovery results or craft setup codes to redirect clients to malicious endpoints, disclosing plaintext gateway credentials.

References