HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-34503 — OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when dev...

Tuesday, March 31, 2026 at 03:16 PM UTC·Source: NIST NVD

Updated: Monday, April 6, 2026 at 02:17 AM UTC

Executive Summary

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection.

Analysis

OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. Attackers with revoked credentials can maintain unauthorized access through existing live sessions until forced reconnection. CVSS Score: 8.1. Published: 2026-03-31T15:16:19.470.

Indicators of Compromise (1)

CVE (1)
CVE-2026-34503
Source Attribution

Originally published by NIST NVD on Mar 31, 2026. Verified by: NIST.

Related Threats