#VU125148 Not Failing Securely ('Failing Open') in OpenClaw - CVE-2026-32970
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to failing open in local gateway helper credential resolution when processing configured but unavailable local auth SecretRefs in local mode. A local user can trigger credential resolution with unavailable gateway.auth.token or gateway.auth.password SecretRefs to disclose sensitive information.
Remote fallback occurs because the helper logic treats configured-but-unavailable local auth inputs as unset.