CVE-2026-32987 | OpenClaw up to 2026.3.12 device-bootstrap.ts authentication replay (GHSA-63f5-hhc7-cx6p / EUVD-2026-17022)
A vulnerability described as critical has been identified in OpenClaw up to 2026.3.12. This affects an unknown part of the file src/infra/device-bootstrap.ts. The manipulation results in authentication bypass by capture-replay.
This vulnerability is cataloged as CVE-2026-32987. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.