CVE-2026-42421

OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attackers can maintain unauthorized access to WebSocket connections after token rotation by exploiting the failure to disconnect existing shared-token sessions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-04-28 19:37

Updated : 2026-06-17 10:47


NVD link : CVE-2026-42421

Mitre link : CVE-2026-42421

CVE.ORG link : CVE-2026-42421


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-613

Insufficient Session Expiration