CVE-2026-32036 | OpenClaw up to 2026.2.25 Gateway Plugin /api/channels authentication by alternate name (GHSA-mwxv-35wr-4vvj / CNNVD-202603-3589)
A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.2.25. This issue affects some unknown processing of the file /api/channels of the component Gateway Plugin. Executing a manipulation can lead to authentication bypass by alternate name.
This vulnerability is tracked as CVE-2026-32036. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.